CSRF: missing request integrity controls
A concise, sanitized overview of a common cross-site request forgery pattern.
What to look for
A state-changing request may be vulnerable when the server relies only on the user's authenticated session and does not verify that the request originated from the intended application flow.
Impact
An attacker may be able to cause an authenticated browser to submit an unintended action on a vulnerable application.
Mitigations
- Use anti-CSRF tokens for state-changing requests.
- Use appropriate SameSite cookie settings.
- Validate Origin or Referer headers where appropriate.
- Require re-authentication or explicit confirmation for sensitive actions.
This page intentionally omits deployable exploit code, live targets, and account-specific data.
Back to PoCs