Cross-Site Request Forgery (CSRF)
An attack that tricks a logged-in user's browser into sending an unwanted, state-changing request to a web application, which accepts it because the browser automatically attaches the user's cookies.
Browsers attach a site's cookies to requests sent to that site, even when the request is triggered by a page on another domain. If an application relies only on a session cookie to authenticate actions, an attacker can host a form or image tag that submits a request to change an email address, transfer funds or alter settings, and the application processes it as if the user intended it. The attacker cannot read the response, so CSRF targets actions rather than data theft.
Any application with cookie-based sessions and state-changing endpoints is potentially exposed, including administration consoles and the web interfaces of devices on internal networks, because a victim's browser can reach addresses that the attacker cannot. CSRF is catalogued as CWE-352 and is routinely tested in web application assessments.
The standard defence is an unpredictable anti-CSRF token tied to the session and verified on every state-changing request; the double-submit cookie pattern is an alternative. The SameSite cookie attribute adds strong protection, and Chromium-based browsers treat cookies without the attribute as Lax by default. Checking the Origin or Referer header provides defence in depth, state-changing operations should never use the GET method, and the CSRF protection built into modern frameworks must remain enabled.
Key points
- Exploits the browser's automatic inclusion of cookies in cross-site requests.
- Targets state-changing actions; the attacker cannot read the response.
- Anti-CSRF tokens and the SameSite cookie attribute are the main defences.
- Catalogued as CWE-352.
Where AiVibe comes in
AiVedha.ai's automated website security audit covers CSRF among more than 170 checks, with severity ratings and remediation steps in its report.