Ace of Spoofing I
You’ve invented a new spoofing attack.
Threat |
|
If the system has end users, this could be a phishing attack that takes advantage of the user already being logged in, such as Cross-Site Request Forgery (CSRF). |
|
CAPEC |
CAPEC-62 - Cross-Site Request Forgery |
ASVS |
4.2.2 - Ensure you are protecting against Cross-Site Request Forgery (CSRF) |
CWE |
CWE-352 - Cross-Site Request Forgery (CSRF) |
Mitigations |
|
|