CSRF: missing request integrity controls

A concise, sanitized overview of a common cross-site request forgery pattern.

What to look for

A state-changing request may be vulnerable when the server relies only on the user's authenticated session and does not verify that the request originated from the intended application flow.

Impact

An attacker may be able to cause an authenticated browser to submit an unintended action on a vulnerable application.

Mitigations

  • Use anti-CSRF tokens for state-changing requests.
  • Use appropriate SameSite cookie settings.
  • Validate Origin or Referer headers where appropriate.
  • Require re-authentication or explicit confirmation for sensitive actions.
Back to PoCs