Reported on Jun 3rd 2021

The /settings/exportToSql endpoint does not have CSRF Protection. This could be used to force download account data and potentially spoof users.

Login to user account. Create the following file and open the page in browser.

// PoC.html
        To verify that you are a human, upload the file that has been downloaded from our website now.
        <a href="">Download Test File</a>

This downloads user's data from the application without user's permission. An attacker can then spoof the user to upload this file into an attacker controlled server.

Potential private information leakage through phishing by exploiting missing CSRF token.

