FintelVentures / fintel-issues

Public repository to track bugs, issues, and feature requests for Fintel
1 stars 0 forks source link

Bug Report (1): No CSRF Protection On Log Out #23

Open Ethicalar opened 5 years ago

Ethicalar commented 5 years ago

Hi Team,

I am a web security researcher and I found this vulnerability in https://fintel.io

Vulnerability Type: No CSRF Protection On Log Out

Description:

I found that an attacker can force any one to logout from there account.There is no CSRF protection so attackers can expire any user sessions by CSRF.

Here is the POC:

Steps to reproduce:

  1. Copy the above poc.
  2. Paste it in notepad.
  3. save it as ex.html. 4, Open it with any browser and test it on any account.

Please let me know if you need more information.

Looking forward to hearing from you.

Best Regards: Hassan Ahmed (ethicalar@gmail.com)