Skip to content

Commit

Permalink
Update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
compaluca authored Jul 13, 2020
1 parent 22295fd commit 4a0efb1
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion casestudies-src/overleaf/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ The lack of the `state` parameter in the Overleaf implementation of
OAuth 2.0 with Google introduced known vulnerabilities.
In particular it was possible to mount a session-swapping attack through a CSRF on the Google Oauth2 callback page at `/users/auth/google_oauth2/callback`. A PoC attack can be found in the [poc.html](./poc.html) file.

The vulneability have been reported to Overleaf developers, that acknowledged the vulnerability and fixed the issue by adding the `state` parameter.
The vulnerability have been reported to Overleaf developers, that acknowledged the vulnerability and fixed the issue by adding the `state` parameter.

## Monitor

Expand Down

0 comments on commit 4a0efb1

Please sign in to comment.