Skip to content

What is Cross-site request forgery?

Also called: CSRF

The short answer

Cross-site request forgery tricks a logged-in user's browser into sending an unwanted request, such as changing an email address, to a site they trust.

Cross-site request forgery, explained

SameSite cookies and anti-CSRF tokens block it.

Questions people ask about Cross-site request forgery

What is Cross-site request forgery?

Cross-site request forgery tricks a logged-in user's browser into sending an unwanted request, such as changing an email address, to a site they trust.

Part of the Web Encyclopedia by Apex Flow Digital. Definitions are general knowledge, kept current, with no invented statistics.

Reviews

We’re early. Real reviews only.

Apex Flow Digital launched recently. Every purchase comes with a request for honest feedback through our help center. When real buyers write real reviews, they go here — with their permission, by name. Until then, this section stays empty. No fakes. No stock photos. No bullshit.

Used something from the catalog? Leave honest feedback →

While you’re here…