Skip to main content

9gag.com Account Takeover with XSS and CSRF

A persistent XSS vulnerability located in the first name field of a 9gag user account and a CSRF vulnerability can be used to reset a victim email.


Date: 2012