Skip to content

Latest commit

 

History

History
31 lines (17 loc) · 693 Bytes

vulnerabilities.md

File metadata and controls

31 lines (17 loc) · 693 Bytes

Vulnerabilities

Vulnerabilites in Fundrequest platform

vulnerability title

*Vulnerability 1 : CSRF to update ETH wallet address in victims account *Vulnerability 2 : 2 : Victims account takeover using password reset link hijacking via host header posinoing

Auditor

@akhilcryptos

Overall Risk Severity (see OWASP Risk Rating)

  • Impact: HIGH
  • Likelihood: HIGH

Proposed solution

*for vulnerability 1 : Add CSRF Token *for vulnerbaility 2 : Refer http://www.skeletonscribe.net/2013/05/practical-http-host-header-attacks.html

Verification

*The team has fixed the reported vulnerabilites