Skip to main content

CSRF - Cross-Site Request Forgery Explained

About 2 min read

CSRF (Cross-Site Request Forgery) is an attack in which an attacker makes a user send an unintended, malicious request to a web service the user is already authenticated with. Because it abuses the credentials (cookies) of the service the user is logged into, the request is processed as if the user had performed the action themselves. Alongside XSS, it is one of the most representative web application attacks. As of 2025, major frameworks (Django, Rails, Next.js) include CSRF protection by default, yet implementation gaps in API endpoints and SPAs continue to be reported.

Where Protection Gaps Tend to Occur

CSRF protection is often implemented for prominent features such as login or money transfers, yet missing from individual settings-change APIs such as those for updating a shipping address or an email address. Framework defaults mainly protect form submissions, so API endpoints added later can remain unprotected unless developers address them explicitly. Because the presence or absence of protection is invisible on screen, vulnerability assessments examine each state-changing request one by one to uncover such gaps. Even the API of a seemingly minor feature matters, as it can give an attacker a way to rewrite a logged-in user's settings.

The Flow of a CSRF Attack

User logs in to a legitimate site
Views the attacker's trap page
Malicious request sent with cookies
Legitimate site executes the action

The Mechanism of a CSRF Attack

The attacker prepares a trap web page and embeds in it a request to a service the user is logged into. For example, if a user views the attacker's page while still logged in to a bank site, the browser automatically sends a money-transfer request to the bank site. Because the browser sends cookies automatically, the bank site cannot distinguish the request from one made by a legitimate user.

Real-World Damage Scenarios

There are cases where, while logged in to an e-commerce site, clicking a link planted by an attacker changes the shipping address to the attacker's address. There have also been reports of damage where viewing a trap page while logged in to a social network results in unintended posts or follows. When combined with session hijacking, the damage becomes even more serious. In online banking, CSRF protection for money-transfer operations is especially important.

Defense Techniques

On the developer side, the standard measure is to embed a CSRF token (a random, unique value) in forms and verify it when the request is made. Setting the SameSite cookie attribute can restrict cross-site cookie transmission. On the user side, the basics are to develop the habit of logging out after important operations and to avoid clicking suspicious links. Protecting your account with a strong random password and enabling multi-factor authentication can mitigate the damage should the worst happen.

Related Terms

Was this article helpful?