Cross-site request forgery
CSRF · Forcing a signed-in user's browser to send a request without the user's knowledge, through a link or form on another site.
- 01
Why it matters
The browser automatically adds the session cookie to every request to a site. If the site does not check that a request really came from the user's own screen, another page can change a password, update an address or start a transfer in the user's name. Per-form tokens and correctly configured cookies prevent this.
- 02
Example
An admin panel's change-email form has no verification token. While signed in, the administrator clicks a link shared on a forum; in the background the account's e-mail is changed to the attacker's.
- 03
Common mistake
Performing important actions through links that work from the address bar. Every state-changing action should be a form submission protected by a token, with re-authentication for critical ones.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.