Digital Securityadvanced1 min read

CSRF

N/A

跨站请求伪造

CSRF · N/A · 跨站请求伪造 · see-surf · cross-site request forgery · XSRF · Digital Security · web · attacks · cookiesDigital Securitycross-site request forgery XSRF

/see-surf/

Also known as: cross-site request forgery, XSRF

Last updated August 8, 2026

Definition

CSRF tricks a victim’s browser into sending an authenticated request to a site the user is logged into, performing actions they did not intend.

Real-World Example

A malicious page could try to submit a “change email” form to your bank while you are still logged in, unless anti-CSRF tokens block it.

References

discuss://translation · public

Translation discussion

Anyone can read and write here. Pick a display name — no email or account. Please keep the thread constructive. Thumb up a rendering you agree with — that helps the editor see consensus; it does not publish the term by itself. You can edit or delete your own comments from this browser; another device or cleared site data cannot.

Community lists who wrote, on which term, and when.

Loading discussion…