Web Hack List

Collected research

CSRF with JSON -- leveraging XHR and CORS

CSRF with JSON – leveraging XHR and CORS

Shows CSRF surviving JSON APIs: an XHR-Level 2 request with withCredentials true and Content-Type text/plain adds no custom header, so CORS skips the preflight, the browser replays the victim's cookies, and a server that never checks Content-Type processes the JSON body. Screenshots of the script, the wire request and the JSON response carry the proof.

Record

Document
CSRF with JSON – leveraging XHR and CORS
Published by
shreeraj.blogspot.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of shreeraj.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .