Your session has expired

Your single sign-on session needs to be re-confirmed before you continue to Confluence.

Confluence admin takeover — one click

target · asserted user · poc 1.0.0

running…

Chain


    

SameSite lab — is a cross-site POST cookie-bearing?

The CSRF leg only works if the browser attaches the admin's JSESSIONID to our cross-site POST. Measured in this browser: not run


  

captured sessions → · /health · api: /api/takeover?url=&username=