This page is experimental and may change significantly in future releases.
Cross-Site Request Forgery (CSRF)
Properties
id: d3f:CWE-352
- name
- Cross-Site Request Forgery (CSRF)
- definition
- The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
- synonyms
- Cross Site Reference Forgery
- synonyms
- Session Riding
- synonyms
- CSRF
- synonyms
- XSRF
Neighbors
Inferred Relationships
Related Countermeasure Techniques
Related Weaknesses
CWE-352 has no related weaknesses in this release.