Two MoTacon attendees are on the left. The MoTaacon logo is in the center, and to the right a prompt to Get Your Ticket.

Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) image
Cross-Site Request Forgery (CSRF) is when your browser gets tricked into doing something, like submitting a form using your login, without you knowing.

It works because browsers send your cookies automatically, even if the request comes from another site. That means an attacker can abuse your login to perform actions on your behalf.

Best way to stop it?

Use CSRF tokens, set SameSite on cookies, and don’t trust requests just because the user’s logged in.
Explore MoT
From test cases to AI-ready quality data: why structure matters image
Learn how to structure and organize test management data as an AI-ready foundation that gives AI systems richer context for testing insights and workflows.
MoT Software Testing Essentials Certificate image
Boost your career in software testing with the MoT Software Testing Essentials Certificate. Learn essential skills, from basic testing techniques to advanced risk analysis, crafted by industry experts.
Into The Motaverse image
Into the MoTaverse is a podcast by Ministry of Testing, hosted by Rosie Sherry, exploring the people, insights, and systems shaping quality in modern software teams.
Subscribe to our newsletter