Solved Users can be tricked into starting connected account association

  • Thread starter Thread starter Kirby
  • Start date Start date
This topic has been solved
K

Kirby

Guest
Starting a connected account association is done via GET, this allows to trick users into clicking a link that starts a connected account association which they might not want to perform.

Example
Start associate account with Google

Suggested Mitigation
Only start the process with POST, if called via GET show a confirmation (or an error if it's not a navigational request).

Continue reading...