The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How "real world" is the CSRF PoC Generator

anonymouse | Last updated: Oct 28, 2016 01:32PM UTC

So here is my dilemma. I found a website that potentially has a CSRF vulnerability and when I proxy my traffic through Burp, generate the PoC html file, CSRF works. The thing as, as far as I know, the CSRF token isnt being leaked in the real world, which more or less means the CSRF exploit fails because I cant pass the token if I dont have it. Does this mean CSRF is more or less mitigated or is it still something that shouldnt be possible even with this CSRF token?

PortSwigger Agent | Last updated: Oct 28, 2016 03:56PM UTC