Forensics Website Penetration Testing Bug In progress

CSRF finding on an endpoint that requires a bearer token

dhleung 13 May 2026, 10:52

You flagged a state-changing endpoint as CSRF-vulnerable, but it only accepts an Authorization: Bearer header, not cookies, so CSRF doesn't apply. Please recheck the auth model.

0 comments

Sign in with your TDesk account to comment.

← Back to all posts