CSRF
Cross-Site Request Forgery
Cross-Site Request Forgery tricks an authenticated user's browser into sending unwanted requests to a web application. The attack works because the browser automatically includes cookies and session tokens with every request to the target site.
Cómo se usa en ciberseguridad
Penetration testers check whether state-changing requests lack anti-CSRF tokens or SameSite cookie attributes. Security engineers implement CSRF protections using synchronizer tokens, double-submit cookies, or SameSite cookie flags. Security architects design authentication flows that resist CSRF by default.
Término relacionado en el glosario: cross site request forgery
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.