Cross-site request forgery
Description
The applications configuration allows an attacker to trick authenticated users into executing actions without their consent.
Impact
Impersonate a user request to execute malicious actions in the application.
Recommendation
Use of tokens in forms to verify requests done by legitimate users.
Threat
Anonymous attacker from the Internet.
Expected Remediation Time
⏱️ 30 minutes.
Requirements
029 - Cookies with security attributes174 - Transactions without a distinguishable patternRules
C Sharp Csrf Protection DisabledRuby Missing Csrf ProtectionPython Csrf Exempt Decorator UsedJavascript Csrf Middleware Order IncorrectPhp Csrf Protection DisabledPhp Csrf Audit Unprotected ActionJava Csrf And Xss Protection DisabledTypescript Csrf Middleware Order IncorrectScala Csrf Headers Bypass