Burp Suite User Forum

Create new post

CSRF

[ | Last updated: Feb 21, 2022 03:32PM UTC

I have a question about some webapplications that for changing passwords of users need to users enter their old password: If a webapplication requier old password of users is it possible to reset a victim's pasword through CSRF attacks ?

Ben, PortSwigger Agent | Last updated: Feb 22, 2022 09:02AM UTC

Hi, As noted in our documentation about CSRF below: https://portswigger.net/web-security/csrf A CSRF attack is not possible if unpredictable request parameters (such as the attacked needing to know the users existing password) are required.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.