CSRF (Cross-Site Request Forgery)
A web attack that tricks authenticated users into unknowingly submitting malicious requests to a site where they're already logged in.
CSRF (also called XSRF or “sea-surf”) is a web security vulnerability where an attacker crafts a malicious request (e.g., changing an email address or transferring funds) and tricks an authenticated user into executing it, typically by embedding it in an image tag, link, or hidden form on a different site.
The attack works because browsers automatically include cookies (including session cookies) with every request to a domain. If the user is logged into their bank and visits a malicious page, the attacker’s request will carry the user’s valid session.
Defenses include CSRF tokens (unique per-session or per-request), SameSite cookie attributes, and requiring re-authentication for sensitive actions. Understanding CSRF is important for teams building or using web applications with shared accounts.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide