Security researcher David Sopas has discovered a Cross Site Request Forgery (CSRF) vulnerability on the RunKeeper website, the official site of the popular GPS fitness-tracking app.
The POST requestto“Account Settings” failed to use the token to validate results in a CSRF vulnerability. This could allow cybercriminals to modify an authorized user’s information by tricking them into clicking on a crafted malicious link.
A persistent vulnerability XSS in the “Account Settings” and profile page poses a potential security risk. Cybercriminals could launch a malicious cyber attack and infect millions of users.
RunKeeper immediately fixed the vulnerability after the researcher alerted it.
📧
Subscribe to the SecNews Newsletter

