Web Hack List

Collected research

Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery - Introducing CSPT2CSRF

Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery

Attacker-controlled input in a URL fragment, query or stored record traverses the path a front end builds for its own API call, rerouting the authenticated request to a different endpoint. That revives CSRF despite SameSite cookies, and a GET-sink primitive can be chained through a file upload gadget into state-changing POST or DELETE calls.

Record

Document
Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery
Researcher
Maxence Schmitt
Published by
blog.doyensec.com
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Maxence Schmitt, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .