What is the name of the attack that tricks a browser into sending an unwanted authenticated request?
Answer
Cross-site request forgery
Answer
Cross-site request forgery
The attack that tricks a browser into sending an unwanted authenticated request is cross-site request forgery.
Cross-site request forgery, commonly abbreviated CSRF or XSRF, abuses the way browsers automatically include credentials such as session cookies. If a victim is logged in to a website, an attacker may lure that browser into submitting a request to the trusted site without the victim intentionally initiating it.
A successful CSRF attack does not necessarily steal the victim's password. Instead, it may cause an unwanted state-changing action, such as changing an account setting or submitting a transaction. Modern defenses include unpredictable anti-CSRF tokens, SameSite cookie attributes, origin checks, and reauthentication for sensitive actions.
CSRF is different from cross-site scripting. XSS injects or executes hostile script in a trusted page, while CSRF abuses a trusted browser session to send a request. The two attacks can also appear together, but they are distinct security problems.
Source: Wikipedia · fact-checked Sept. 2026