High severity Vulnerability

Cross-Site Request Forgery (CSRF)

A logged-in browser is tricked into submitting an action the user never intended.

Overview

CSRF relies on the browser automatically attaching cookies to cross-origin requests.\nIf an endpoint trusts "the session cookie equals intent", an attacker's page can change a password, transfer funds or alter settings while the victim is logged in.\nDefence is an unpredictable per-session token bound into every state-changing request.

Indicators of Compromise

Signals that suggest this is present on a system.

  • State-changing GET endpoints
  • Missing or static CSRF tokens
  • No SameSite cookie attribute

Controls that stop it

  • Harden TLS and Security Headers

    Serve everything over TLS with HSTS so downgrades are impossible, set a modern Content-Security-Policy, enable HSTS preload, deny framing with frame-ancestors, and switch on Referrer-Policy and Permissions-Policy. Disable unused legacy protocols and cipher suites rather than leaving them configured for compatibility.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used