# Description
Mutations are `saveRecord` or `createProcess` queries used in Graphql. SuiteCRM prevents CSRF in this functionality by sending a POST request with a X-Xsrf-Token header. the bug here is that, when we send a GET request, the backend does not expect the X-Xsrf-Token header. Using this, an attacker cound leverage this to bypass the existing CSRF protection.
# Proof of Concept :
* Save it with html extension and click on submit request and the user account is created .
#URL used in “GET“ request
“`Read More