Don't have an account? Sign up
If you're already signed up, please sign in
CSRF — an attack that tricks an authenticated browser into sending an unwanted state-changing request to a trusted site.
The vulnerability arises when an application trusts unvalidated input, a request, a traffic source, or a network channel. Impact depends on the attack surface and can include code execution, session theft, data modification, or denial of service.
CSRF — an attack that tricks an authenticated browser into sending an unwanted state-changing request to a trusted site.
An attacker crafts data or traffic so an application, browser, database, or user performs an unintended action. The exact path depends on the vulnerability type.
Use input validation and contextual output encoding, parameterized queries, session protection, least privilege, updates, rate controls, a WAF, and monitoring. No single filter replaces secure development.