Hacker News

laserspeed
Client-Side Path Traversal: Exploiting CSRF in Header-Based Auth Scenarios blog.kulkan.com

laserspeedop7 hours ago

In this detailed blog post, Lucas Cebrero Lell walks us through CSPT vulnerabilities and how valuable they are in order to exploit CSRF in apps which have moved away from the typical auth Cookies. There's also a Lab available in github based on React and Node which serves as a sample vulnerable app to try and exploit CSPT.

hn-front (c) 2024 voximity
source