Exploit steps
- Log into the Firefox https://lastpass.com website client (not browser extension).
- Add a new site and set the URL to this page. Alternatively, the attacker can share a malicious site with you.
- Click launch on your newly added site.
Exploit
Leaked CSRF token: (not loaded yet)