Summary
I discovered a Cross-Site Request Forgery (CSRF) vulnerability in Amplenote's subscription flow.
An attacker can craft a malicious webpage that automatically submits a request to the subscription endpoint while the victim is logged in to Amplenote. If the victim visits the attacker's page, the request is processed using the victim's authenticated session and can force the victim's subscription to be changed/downgraded to the free Personal plan.
Affected Endpoints
Subscription endpoint:
https:
Personal-plan flow:
https:
Steps to Reproduce
Create or use an Amplenote account with an active paid subscription.
Log in to the account normally.
go to https:
Prepare a CSRF PoC that submits the relevant subscription request to:
https:
The cross-origin request is processed using the victim's existing authenticated session.
After the request is completed, check the victim's subscription status.
The subscription is changed/downgraded to the Personal plan without the victim intentionally performing the subscription-change action.
Proof of Concept
The PoC should reproduce the exact request generated by the legitimate Personal-plan subscription flow and submit it cross-origin.
For responsible disclosure, I recommend including the exact captured request/parameters in the report rather than relying only on the URL, because this allows the Amplenote security team to reproduce the issue accurately.
Security Impact
An attacker could potentially force an authenticated user to change their subscription without their consent.
For a user on a paid plan, this can result in:
Unauthorized downgrade from a paid subscription to the free Personal plan.
Loss of access to features available only on the paid subscription.
Potential disruption to the victim's workflow.
Potential financial/business impact for Amplenote because subscription state can be changed through an unauthorized cross-site request.
Unauthorized modification of account/subscription settings.
Amplenote's documentation confirms that Personal is the free plan and that paid subscription levels provide additional functionality.
Expected Behavior
Changing or downgrading a user's subscription should require an intentional action from the authenticated user and should not be possible through a cross-origin request initiated by an attacker.
The subscription-changing request should also be protected against CSRF, for example through an appropriate CSRF token and/or robust Origin/Referer validation.
Actual Behavior
A cross-origin request can be used to trigger the subscription-change flow in the victim's authenticated session and force the account toward the Personal plan.
Suggested Severity
High, if the downgrade can be performed against an existing paid subscription without user interaction or confirmation.
The final severity should depend on whether the downgrade immediately terminates paid benefits, cancels the billing/subscription state, or otherwise causes additional financial or account impact.