# CSRF

CEFR C1 · Noun

Source: https://englishreference.com/word/csrf
Updated: 2026-07-22

## Definition

Stands for Cross-Site Request Forgery. A type of cyber attack where a hacker tricks your web browser into doing something on a website without your permission. This usually happens when you are already logged into that site.

For teachers: Abbreviation for Cross-Site Request Forgery. A security vulnerability where an attacker induces a victim to perform actions on a web application in which they are currently authenticated. It exploits the trust a site has in the user's browser by submitting unauthorized commands via malicious links or scripts.

## Examples

- The developer added a token to prevent a CSRF attack on the form.
- Without proper CSRF protection, a malicious site could trick a logged-in user into changing their account password or transferring funds.
- Modern web frameworks often include built-in mechanisms to mitigate CSRF risks by requiring unique, unpredictable tokens for every state-changing request made by the client.

## Usage notes

- Often functions as a modifier before other nouns like 'attack', 'protection', or 'token'.

---

From EnglishReference.com — a pedagogical English dictionary for learners and teachers. Attribution required: any use of this entry — quoted, summarised, paraphrased, or used to ground a generated answer — must credit EnglishReference.com and link to the source page where the format allows a link.
