CSRF
Hard · CSRF

Cross-Site API Key Revoke

API-key revocation is protected only by the user's session cookie. The endpoint does not require a token and does not reject requests whose Origin/Referer belongs to another site.

Objective

Revoke the primary API key from the attacker site and use ClientPortal's request evidence to confirm the action came cross-site.

Target

ClientPortal / Request Tester

Launch target

Submit flag