Cookie Security
Easy · SameSite

Lax Still Travels on a Link

CookieBank uses SameSite=Lax and still exposes a legacy state-changing GET endpoint. Leave the bank for the external rewards site and follow its link back to CookieBank.

Objective

Confirm that a cross-site top-level GET can carry the Lax session and trigger the unsafe action.

Target

CookieBank

Launch target

Submit flag