← All labs
CSRF Level 4 / 6 Medium

Weak Referer Check

The server validates the Referer header — but poorly. Bypass the check.

Account settings — Referer checked

This endpoint rejects requests whose Referer doesn't look like it came from the site. Supply the Referer your attacker page would send along with your forged request.

Signed in as

victim

Current email on file

victim@uncrypt.io

This site's host

www.playground.uncrypt.net

Attacker page HTML:

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of Uncrypt Playground is not part of the target.