CSRF abuses an authenticated browser
Cross-site request forgery makes the user's own browser perform an action on a site where they are already logged in.
The browser helpfully attaches the session, as designed, so the request is entirely valid. The user did not intend it and the server cannot tell. The defence is requiring something the attacking site cannot obtain, typically a token, which is why modern frameworks include one by default.
More on Web application security
- XSS turns trusted pages into script deliveryIt comes out in your own voice
- Output encoding is context-specificThe plug has to match the socket
- Path traversal escapes the intended file areaTwo dots at a time
- File upload security is more than extension checkingThe label is a claim, not a check
- Open redirects lend trusted domains to phishingYour livery, their destination
- Security headers shape browser behaviourInstructions the browser follows
