Glossary Security

CSRF

CSRF (cross-site request forgery) is an attack that tricks a logged-in user's browser into sending an unwanted request to a site where they are authenticated.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

Because browsers attach cookies automatically, a malicious page can make your browser submit a form to your bank. Defences are anti-CSRF tokens that an attacker cannot guess, SameSite cookies and checking the Origin header. It differs from Cross-site scripting (XSS): CSRF abuses the site's trust in your browser, XSS abuses your browser's trust in the site.

See also

  • Glossary Cross-site scripting (XSS)
    Cross-site scripting (XSS) is a vulnerability in which an attacker gets a website to deliver malicious script to other users' browsers.
  • Glossary Cookie
    A cookie is a small piece of data a website stores in your browser and sends back with later requests.
  • Glossary CORS
    CORS (Cross-Origin Resource Sharing) is the browser mechanism that lets a server allow web pages from other origins to read its responses.
AdSense Placeholder
Slot: footer_leaderboard