← Fiverr

2014 CSRF vulnerability — millions of accounts at risk

2014 Unknown records affected Share on X

Data compromised

Account takeover risk; email addresses

Technical writeup

Critical Cross-Site Request Forgery (CSRF) vulnerability discovered on Fiverr.com. Attackers could compromise user accounts by tricking victims into visiting a malicious webpage. If a victim was logged in, the attacker could replace the account email and use password reset to take over the account. Researcher Mohamed Abdelbaset reported the flaw; Fiverr reportedly ignored it before public disclosure.

Root cause

CSRF vulnerability; insufficient request validation.

References