5 ms·
Client-Side Path Traversal: Exploiting CSRF in Header-Based Auth Scenarios
- laserspeed 11mo agoIn this detailed blog post, Lucas Cebrero Lell walks us through CSPT vulnerabilities and how valuable they are in order to exploit CSRF in apps which have moved away from the typical auth Cookies. There's also a Lab available in github based on React and Node which serves as a sample vulnerable app to try and exploit CSPT.