CSRF Proof of Concept - BDServer

This page demonstrates the CSRF vulnerability in BDServer.

If you are logged into BDServer at localhost:8080, your profile has been modified.

What happened?

Why this works

BDServer uses GET requests for state-changing operations and has no CSRF protection. When your browser loads this page, it fetches the image URLs above. Since you're logged in, your session cookie is sent with each request, authenticating the malicious actions as if you performed them yourself.