☁️ Daily Practice, two formats, one streak, fresh every day at midnight UTC
Puzzle #197securityintermediate
One Click Attack
A banking app lets authenticated users transfer money via POST /transfer?to=bob&amount=1000. The app uses session cookies. An attacker embeds this HTML on an external site: <img src="https://bank.com/transfer?to=hacker&amount=5000">.
Why does this attack work?