☁️ Daily Practice, two formats, one streak, fresh every day at midnight UTC

Puzzle #197securityintermediate

One Click Attack

A banking app lets authenticated users transfer money via POST /transfer?to=bob&amount=1000. The app uses session cookies. An attacker embeds this HTML on an external site: <img src="https://bank.com/transfer?to=hacker&amount=5000">.

Why does this attack work?