{"id":650,"date":"2014-06-30T10:04:10","date_gmt":"2014-06-30T10:04:10","guid":{"rendered":"https:\/\/www.varutra.com\/blog\/?p=650"},"modified":"2022-12-02T17:01:06","modified_gmt":"2022-12-02T11:31:06","slug":"csrf-vulnerability-on-linkedin","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/","title":{"rendered":"CSRF Vulnerability on LinkedIn"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1-1024x573.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"csrf Copy - Varutra Consulting\"><br \/>\n<b><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf_linkedin.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-651\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf_linkedin-300x208.png\" alt=\"csrf_linkedin\" width=\"300\" height=\"208\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf_linkedin-300x208.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf_linkedin-768x533.png 768w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf_linkedin.png 799w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/b><\/p>\n<p style=\"text-align: justify\">In previous<a href=\"https:\/\/www.varutra.com\/blog\/?p=281\"> blog <\/a> we have seen a critical vulnerability in LinkedIn password reset module allowing an attackers to compromise LinkedIn user\u2019s account and how helpless a LinkedIn user in case of an actual compromise of his \/ her account in real world scenario.<\/p>\n<p style=\"text-align: justify\"><b>Here is a new vulnerability Cross-Site Request Forgery, CSRF present on LinkedIn Recommendation Section, which allows attacker to delete any Recommendation of Any user.\u00a0 <\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Lets us understand the CSRF issue and simplicity of this attack.<\/b><\/h3>\n<p>1. Attacker \/ malicious LinkedIn user can check the recommendation given by LinkedIn User 1 to LinkedIn User 2.<\/p>\n<p>2. Attacker logs into LinkedIn account, goes to the web page source and search for strings such as \u201cRecommendation for USERNAME\u201d.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-653 size-medium\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf2-300x138.png\" alt=\"csrf 2\" width=\"300\" height=\"138\" \/><\/a><\/p>\n<p style=\"text-align: center\">\u00a0Figure: Web page source shows the recommendation details with a unique Id \u201d515940281\u201d for User 1\u2019s recommendations to User 2.<\/p>\n<p>&nbsp;<\/p>\n<p>3. To craft a malicious CSRF link attacker goes to <strong>Manage Recommendation<\/strong> area and check for any recommendations he has posted for others. \u00a0Clicks on it and copy the URL for any one recommendation.<\/p>\n<p>The URL will be<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/recommendations?dep=&amp;recID=515830421&amp;goback=%2Enas_*1_*1_*1%2Eprs\">https:\/\/www.linkedin.com\/recommendations?dep=&amp;recID=515830421&amp;goback=%2Enas_*1_*1_*1%2Eprs<\/a><\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-652 size-medium\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf1-300x187.png\" alt=\"Cross-Site Request Forgery Vulnerability\" width=\"300\" height=\"187\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf1-300x187.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf1-768x480.png 768w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf1.png 844w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center\"><span style=\"font-size: small\">Figure: Analyzing and collecting URL for Displaying and Withdrawing a User&#8217;s recommendation.<br \/>\n<\/span><\/p>\n<p>\u00a04. Now same way the URL to withdraw any given recommendation by the attacker is<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/recommendations?wdr=&amp;recID=515830421&amp;goback=%2Enas_*1_*1_*1%2Eprs\">https:\/\/www.linkedin.com\/recommendations?wdr=&amp;recID=515830421&amp;goback=%2Enas_*1_*1_*1%2Eprs<\/a><\/p>\n<p>The only difference is to change the parameter from \u2018dep\u2019 to \u2018wdr\u2019.<\/p>\n<p>Craft a URL for removing or withdrawing recommendation from User 1 to User 2 is<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/recommendations?wdr=&amp;recID=515940281\">https:\/\/www.linkedin.com\/recommendations?wdr=&amp;recID=515940281<\/a><\/p>\n<p>This is the shortest and simplest form of the vulnerable CSRF link.<\/p>\n<p>5. Send this URL to User 1 in an email. More dangerously, the same CSRF link can be send using LinkedIn mail feature.<\/p>\n<p>6. On clicking this link by User 1 the selected recommendation given by User 1 to User 2 will be withdrawn or deleted.<\/p>\n<p>&nbsp;<\/p>\n<p><em><strong>On reporting this issue LinkedIn was prompt to acknowledge the vulnerability and have mitigated it.<\/strong><\/em><\/p>\n<p>More can be read at <a title=\"CSRF on LinkedIn\" href=\"http:\/\/packetstormsecurity.com\/files\/127259\/\">http:\/\/packetstormsecurity.com\/files\/127259\/<\/a><\/p>\n<p>Written By,<\/p>\n<p><em>Attack &amp; PenTest Team,<\/em><\/p>\n<p><em>Varutra Consulting<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>In previous blog we have seen a critical vulnerability in LinkedIn password reset module allowing an attackers to compromise LinkedIn user\u2019s account and how helpless&#8230;<\/p>\n","protected":false},"author":3,"featured_media":3240,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[140,276,261,266,267],"tags":[59,60,61],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.6.3 - aioseo.com -->\n\t\t<meta name=\"description\" content=\"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user&#039;s private information.\" \/>\n\t\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.6.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn\" \/>\n\t\t<meta property=\"og:description\" content=\"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user&#039;s private information.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1250\" \/>\n\t\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t\t<meta property=\"article:section\" content=\"Case Study\" \/>\n\t\t<meta property=\"article:tag\" content=\"csrf attack\" \/>\n\t\t<meta property=\"article:tag\" content=\"linkedin cross site request frogery attack\" \/>\n\t\t<meta property=\"article:tag\" content=\"linkedin csrf\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2014-06-30T10:04:10+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T11:31:06+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn\" \/>\n\t\t<meta name=\"twitter:description\" content=\"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user&#039;s private information.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpadmin\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#article\",\"name\":\"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn\",\"headline\":\"CSRF Vulnerability on LinkedIn\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2014\\\/06\\\/csrf-Copy-1.png\",\"width\":1250,\"height\":700,\"caption\":\"csrf - Copy\"},\"datePublished\":\"2014-06-30T10:04:10+05:30\",\"dateModified\":\"2022-12-02T17:01:06+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#webpage\"},\"articleSection\":\"Case Study, Cyber Attack, Ethical Hacking, Security Advisory, Social Networking Security, CSRF attack, Linkedin Cross Site Request Frogery Attack, LinkedIn CSRF\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"nextItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#listItem\"},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#listItem\",\"position\":2,\"name\":\"CSRF Vulnerability on LinkedIn\",\"previousItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\"}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/\",\"name\":\"kalpadmin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"kalpadmin\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/\",\"name\":\"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn\",\"description\":\"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user's private information.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2014\\\/06\\\/csrf-Copy-1.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#mainImage\",\"width\":1250,\"height\":700,\"caption\":\"csrf - Copy\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/csrf-vulnerability-on-linkedin\\\/#mainImage\"},\"datePublished\":\"2014-06-30T10:04:10+05:30\",\"dateModified\":\"2022-12-02T17:01:06+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn<\/title>\n\n","aioseo_head_json":{"title":"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn","description":"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user's private information.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn","og:description":"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user's private information.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png","og:image:width":"1250","og:image:height":"700","article:section":"Case Study","article:tag":["csrf attack","linkedin cross site request frogery attack","linkedin csrf"],"article:published_time":"2014-06-30T10:04:10+00:00","article:modified_time":"2022-12-02T11:31:06+00:00","twitter:card":"summary_large_image","twitter:title":"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn","twitter:description":"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user's private information.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png","twitter:label1":"Written by","twitter:data1":"kalpadmin","twitter:label2":"Est. reading time","twitter:data2":"2 minutes","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#article","name":"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn","headline":"CSRF Vulnerability on LinkedIn","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png","width":1250,"height":700,"caption":"csrf - Copy"},"datePublished":"2014-06-30T10:04:10+05:30","dateModified":"2022-12-02T17:01:06+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#webpage"},"articleSection":"Case Study, Cyber Attack, Ethical Hacking, Security Advisory, Social Networking Security, CSRF attack, Linkedin Cross Site Request Frogery Attack, LinkedIn CSRF"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3\/","nextItem":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#listItem"},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#listItem","position":2,"name":"CSRF Vulnerability on LinkedIn","previousItem":"https:\/\/www.varutra.com\/varutravrt3\/#listItem"}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/","name":"kalpadmin","image":{"@type":"ImageObject","@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g","width":96,"height":96,"caption":"kalpadmin"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/","name":"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn","description":"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user's private information.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#mainImage","width":1250,"height":700,"caption":"csrf - Copy"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/#mainImage"},"datePublished":"2014-06-30T10:04:10+05:30","dateModified":"2022-12-02T17:01:06+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]}},"aioseo_meta_data":{"post_id":"650","title":"CSRF (Cross Site Request Forgery) Vulnerability on LinkedIn","description":"A critical vulnerability found on the LinkedIn password reset module allows the hacker to collect the user's private information.","keywords":[],"keyphrases":"{\"focus\":{\"keyphrase\":\"CSRF\",\"score\":80,\"analysis\":{\"keyphraseInTitle\":{\"title\":\"Focus keyphrase in SEO title\",\"description\":\"Focus keyphrase found in SEO title.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInDescription\":{\"title\":\"Focus keyphrase in meta description\",\"description\":\"Focus keyphrase not found in meta description.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseLength\":{\"title\":\"Focus keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":1},\"keyphraseInURL\":{\"title\":\"Focus keyphrase in URL\",\"description\":\"Focus keyphrase used in the URL.\",\"score\":5,\"maxScore\":5,\"error\":0},\"keyphraseInIntroduction\":{\"title\":\"Focus keyphrase in introduction\",\"description\":\"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInSubHeadings\":{\"title\":\"Focus keyphrase in Subheadings\",\"description\":\"Your H2 or H3 subheading reflects the topic of your copy. Good job!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInImageAlt\":{\"title\":\"Focus keyphrase in image alt attributes\",\"description\":\"Focus keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}}},\"additional\":[{\"keyphrase\":\"Cross-Site Request Forgery\",\"score\":67,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase not found in meta description.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":3},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}}},{\"keyphrase\":\"Vulnerability\",\"score\":100,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":1},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase appears in the first paragraph. Well done!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}}}]}","primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/06\/csrf-Copy-1.png","og_image_width":"1250","og_image_height":"700","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Case Study","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"open_ai":null,"created":"2021-10-27 15:18:10","updated":"2022-12-02 11:31:38"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/case-study\/\" title=\"Case Study\">Case Study<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tCSRF Vulnerability on LinkedIn\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Case Study","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/case-study\/"},{"label":"CSRF Vulnerability on LinkedIn","link":"https:\/\/www.varutra.com\/varutravrt3\/csrf-vulnerability-on-linkedin\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/650"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=650"}],"version-history":[{"count":4,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/650\/revisions"}],"predecessor-version":[{"id":20378,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/650\/revisions\/20378"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/3240"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}