HackerOne Disclosed Reports - 2025-10-10

0 Replies, 139 Views

Logo
Low
resolved

CSRF allowing unauthorized modification of user Notes on ███████


Bug reported by Mahmoud Khaled was disclosed at October 10, 2025, 6:37 pm   |   Cross-Site Request Forgery (CSRF)

A CSRF vulnerability was discovered that allowed unauthorized modification of user notes. The vulnerability was present in the endpoint that handled saving the notes. The endpoint did not implement proper CSRF protection, allowing an attacker to craft a malicious link that could be used to modify or delete the victim's notes. The complexity of the attack was that the attacker needed to be a member of the same organization as the victim in order to obtain the victim's correct ID, which was required to carry out the attack.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-10-10 - by hashXploiter - 10-11-2025, 12:30 PM



Users browsing this thread: