CWECompoundStable20 recent CVEs

CWE-352Cross-Site Request Forgery (CSRF)

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Common consequences

Potential mitigations

Related CWEs

Recent CVEs classified under this CWE