CWE-352
Overview
- CWE ID
- 352
- CWE Name
- Cross-Site Request Forgery (CSRF)
- CWE Abstraction
- Compound
- CWE structure
- Composite
- CWE Status
- Stable
Description
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Extended Description
When a web server is designed to receive a request from a client without any mechanism for verifying that it was intentionally sent, then it might be possible for an attacker to trick a client into making an unintentional request to the web server which w