XSRF and threat ratings
portswigger.net | blog | #sql-injection | #web-security | #penetration-testing | #csrf | #xsrf | #threat-rating
Summary
XSRF changes how we rate other vulnerabilities: SQL injection restricted to admins can be exploited via XSRF just like an intended admin query feature, so both deserve equally serious ratings.
- Published
- Collected
Skip to content