Collected research
Multiple Facebook Messenger CSRF's
Facebook Messenger Multiple CSRF Vulnerabilities
Two CSRF holes in messenger.com: the send_messages and delete_thread endpoints accepted cross-site POST requests without checking a token, so a page the victim visits could send messages from their account to any user or delete their message threads. Both were fixed by Facebook.
Record
- Document
- Facebook Messenger Multiple CSRF Vulnerabilities
- Researcher
- Mazin Ahmed and @mazen160
- Published by
- Mazin Ahmed
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mazin Ahmed and @mazen160, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .