An attacker found a CSRF vulnerability in Instagram that allowed changing comment keyword filters on behalf of other users. After reporting, Facebook's internal research identified additional vulnerable endpoints, potentially leading to account takeover. The initial vulnerability involved the lack of CSRF token and Origin checks in a specific POST request.

1m read timeFrom infosecwriteups.com
Post cover image
Table of contents
CSRF in InstagramDescription/Impact:

Sort: