Cross-Site-Request Forgery (CSRF)

From Embedded Lab Vienna for IoT & Security
Revision as of 16:48, 28 December 2020 by DLechner (talk | contribs) (Removed redirect to Basic:Cross-Site-Request-Forgery)
Jump to navigation Jump to search


Victims are executing actions unwillingly on Webapplications they are authenticated to. Some of those actions are

  • changing password
  • changing email-addresse
  • changing user-role
  • create account
  • transfer money