Standardlikelihood: Highseverity: Very HighDraft
CAPEC-62Cross Site Request Forgery
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
Very High
Description
An attacker crafts malicious web links and distributes them (via web pages, email, etc.), typically in a targeted manner, hoping to induce users to click on the link and execute the malicious action against some third-party application. If successful, the action embedded in the malicious link will be processed and accepted by the targeted application with the users' privilege level. This type of attack leverages the persistence and implicit trust placed in user session cookies by many web applications today. In such an architecture, once the user authenticates to an application and a session cookie is created on the user's system, all following transactions for that session are authenticated using that cookie including potential actions initiated by an attacker and simply "riding" the existing session cookie.
Related weaknesses· 5
Related attack patterns· 1
Exploits5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Cross-Site Request Forgery (CSRF)cwe-352 | 100% | live |
| Weakness | Improper Control of a Resource Through its Lifetimecwe-664 | 100% | live |
| Weakness | Sensitive Cookie with Improper SameSite Attributecwe-1275 | 100% | live |
| Weakness | Incorrect Permission Assignment for Critical Resourcecwe-732 | 100% | live |
| Weakness | Missing Authentication for Critical Functioncwe-306 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.