CSRF abuses an authenticated browser

Cross-site request forgery makes the user's own browser perform an action on a site where they are already logged in.

The browser helpfully attaches the session, as designed, so the request is entirely valid. The user did not intend it and the server cannot tell. The defence is requiring something the attacking site cannot obtain, typically a token, which is why modern frameworks include one by default.

More on Web application security