June 3, 2026

CSRF Protection Bypass via Method Confusion Leading to Full Account Takeover

The TV login sync feature on tvs.redacted.com allows an attacker to fully take over any redacted user account. By converting a POST request…

Unknown

1 min read