CSRF
CSRF is possible when ...
GET Requests Exploits
Invisible mage Loading
Link clicking
Form Auto-Submission
Silent Form Auto-Submission (No Redirection)
POST Requests Exploits
Form Auto-Submission
Silent Form Auto-Submission (No Redirection)
DELETE / PUT Requests Exploits
Protection Bypass
Referer Header Check Bypass
Send a request with no Referer header
Referer headerChain CSRF vulnerability with XSS
HTTP Method Check Bypass through HTTP Method Tunneling :
X-HTTP-Method-Override Method
X-HTTP-Method-Override Method_method Parameter Method
_method Parameter MethodReferences :
Last updated