T09 · Insecure Skill Coding Practices
- Location
src/rsvp.ts:146- Finding
Speculative RSVP Endpoint Probing Can Cause Repeated Authenticated State Changes
- Content
View full analysis
> { const payloads: Array> = [ { event_id: eventId, response }, { event_id: eventId, status: response }, { event_id: eventId, answer: response }, { event_id: eventId, rsvp: response }, { event_id: eventId, value: response }, { event_id: eventId, event_uuid: eventId, response }, ]; if (response === 'yes') { payloads.push({ event_id: eventId, going: true }); } if (response === 'no') { payloads.push({ event_id: eventId, going: false }); } return payloads; } ``` ```ts const endpoints = [ `${LUMA_BASE_URL}/api/v2/event/rsvp`, `${LUMA_BASE_URL}/api/v1/event/rsvp`, `${LUMA_BASE_URL}/api/event/rsvp`, `${LUMA_BASE_URL}/api/v2/event/${eventId}/rsvp`, `${LUMA_BASE_URL}/api/v1/event/${eventId}/rsvp`, `${LUMA_BASE_URL}/api/rsvp`, ]; const payloads = buildPayloads(eventId, normalized); for (const endpoint of endpoints) { for (const payload of payloads) { const headers: Record = { 'User-Agent': USER_AGENT, 'Accept': 'application/json, text/plain, */*', 'Content-Type': 'application/json', 'X-Requested-With': 'XMLHttpRequest', 'Cookie': cookies, }; if (csrfToken) { headers['x-csrf-token'] = csrfToken; headers['x-csrf'] = csrfToken; } const responseResult = await fetchWithBackoff( endpoint, { method: 'POST', headers, body: JSON.stringify(payload), }, LUMA_BACKOFF_OPTIONS ); const text = await responseResult.text(); if (responseResult.ok) { return { success: true, messag ...[truncated 3538 chars]- Remediation
View remediation
