skip to content

questions

4

With no script at all, what requests can a hostile page emit at a clinic's cookie-authenticated booking endpoints?

level: middleimportance: must knowfreq 60%

basics

~20 s

Plain markup can emit a GET through any subresource or navigation, and a form POST whose body is one of three encodings: application/x-www-form-urlencoded, multipart/form-data or text/plain. It cannot add a request header field of its own.

open as a page

A clinic's cancel-appointment endpoint acts on GET and the attacker never sees the response — why is the forgery still complete?

level: seniorimportance: should knowfreq 50%

basics

~20 s

The cancellation happens when the server handles the request, so reading the response adds nothing for the attacker. Safety in RFC 9110 is a contract about what a client may assume, not enforcement — an implementation is free to change state on GET, and this one has.

open as a page

What is login CSRF against a clinic booking site, and why is signing a victim into the attacker's own account worth doing?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Login CSRF forges a sign-in with the attacker's own credentials, so the victim's browser ends up holding the attacker's session. Everything the victim then does — pets added, a card saved, appointments booked — accrues to an account the attacker can log into and read.

open as a page