Skip to content

CSRF Protection Bypass for JSON APIs #18

@kasimlyee

Description

@kasimlyee
Image

Problem:
CSRF middleware ONLY validates tokens in form() data (URL-encoded or multipart)
API endpoints that accept application/json are completely unprotected
Attackers can bypass CSRF by sending JSON payloads

Impact: High - All JSON API endpoints vulnerable to CSRF attacks PoC

Metadata

Metadata

Assignees

Labels

bugSomething isn't workinggreat findingone of the eye opening finds ever

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions