|
|
|
|
|
by Xk
5187 days ago
|
|
Either you do it for everything, or you do it for only POST and you end up missing half of the vulnerabilities. Correct me if I'm wrong, but your CSRF attack used a GET request, did it not? [1] Web applications make state-changing operations on GET requests. You might not like it, but they do. [1] <img src="https://mail.google.com/mail/u/0/?logout style="display: none;" /> |
|
but when developer made a mistake with GET it is 100% his problem - it's out of question. he should be punished :D