In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross Site Request Forgery vulnerabilities in an interactive lesson.
Start learningSpree is an open source e-commerce framework for Ruby on Rails.
Spree contains a flaw in the API as HTTP requests do not require multiple steps, explicit confirmation, or a unique token when performing certain sensitive actions. By tricking a user into following a specially crafted link, a context-dependent attacker can perform a Cross-site Request Forgery (CSRF / XSRF) attack causing the victim to disclose potentially sensitive information to attackers.