Hacker News new | ask | show | jobs
by jere 4780 days ago
>However, checking the referer is considered to be a weaker from of CSRF protection. For example, open redirect vulnerabilities can be used to exploit GET-based requests that are protected with a referer check.

https://owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF...