Collected research
Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery - Introducing CSPT2CSRF
Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery
Attacker-controlled input in a URL fragment, query or stored record traverses the path a front end builds for its own API call, rerouting the authenticated request to a different endpoint. That revives CSRF despite SameSite cookies, and a GET-sink primitive can be chained through a file upload gadget into state-changing POST or DELETE calls.
Record
- Document
- Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery
- Researcher
- Maxence Schmitt
- Published by
- blog.doyensec.com
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Maxence Schmitt, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .