Complete application ownage via Multi-POST XSRF

Aug. 10, 2014

We had determined that the primary threat would be for a user to escalate privileges and access information from other accounts. In order to achieve this goal we concentrated on t…