Web Hack List

Collected research

Multiple Facebook Messenger CSRF's

Facebook Messenger Multiple CSRF Vulnerabilities

Two CSRF holes in messenger.com: the send_messages and delete_thread endpoints accepted cross-site POST requests without checking a token, so a page the victim visits could send messages from their account to any user or delete their message threads. Both were fixed by Facebook.

Record

Document
Facebook Messenger Multiple CSRF Vulnerabilities
Researcher
Mazin Ahmed and @mazen160
Published by
Mazin Ahmed
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mazin Ahmed and @mazen160, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .