Browsers attach cookies to every request to a domain — including requests a hostile page causes. If example.com/evil submits a hidden form to bank.com/transfer while the victim is logged in, the bank sees a perfectly authenticated request. The browser cannot tell intent, only credentials.
The standard defences are CSRF tokens (a secret the real page knows and forgeries do not), SameSite cookies, and checking the Origin header. Modern frameworks ship most of it; the vulnerability survives where hand-rolled endpoints quietly skip it.
Related terms
Cross-site scripting (XSS)
An attack that injects hostile JavaScript into a page other people view — the browser runs the attacker's code with the victim's session.
Session hijacking
Stealing the token that proves a logged-in session — whoever holds it is you, no password needed.
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
