General Information

Predictable Anti-CSRF Token Abuse

Variants:
Direct 

Vector Type:
Attack

Relevance:
Generic

Layer:
Application-Level

Platforms:
Any

Target Type:
Web Application

Affected Mechanisms:
Anti-CSRF

Invented In:
13/07/2001

Added In:
24/12/2014


Vector Operation Method:
Consistent, simple or predictable antiCSRF token can be used by attackers to bypass protection mechanisms.


Direct Variant:

Predictable Anti-CSRF Token Abuse

Variant Title:
Predictable Anti-CSRF Token Abuse

Typical Severity:
Medium

Resources:

White Papers:

Learn More: