Hacker News new | past | comments | ask | show | jobs | submit login
ActBlue CSRF Security Vulnerability Responsible Disclosure (rajk.me)
8 points by quantumtremor on June 15, 2016 | hide | past | favorite | 1 comment



Pasting the introduction here.

> Non-technical introduction. ActBlue is a non-profit that organizes fundraising efforts for Democratic causes; so far they have facilitated over a billion dollars in donations. This page details a security vulnerability in the ActBlue donation system.

> tl;dr This vulnerability affects over three million individuals who have donated to a Democratic cause using ActBlue Express Lane. Specifically, the ActBlue donation system can be exploited to appropriate false donations towards either the Hillary Clinton or Bernie Sanders campaigns. Using cross-site request forgery, previous donors can be tricked into donating to other Democratic candidates or causes.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: