3 ms·
The referer header can easily be forged. The whole point of a CSRF attack is to turn a user's credentials against him.
by sdevlin 15y ago
The referer header can easily be forged. The whole point of a CSRF attack is to turn a user's credentials against him.