2014 CSRF vulnerability — millions of accounts at risk
Data compromised
Account takeover risk; email addresses
Technical writeup
Critical Cross-Site Request Forgery (CSRF) vulnerability discovered on Fiverr.com. Attackers could compromise user accounts by tricking victims into visiting a malicious webpage. If a victim was logged in, the attacker could replace the account email and use password reset to take over the account. Researcher Mohamed Abdelbaset reported the flaw; Fiverr reportedly ignored it before public disclosure.
Root cause
CSRF vulnerability; insufficient request validation.