Mitigating Cross-Site Request Forgery Vulnerabilities: An Examination of Prevention Systems

Yuvraj Singh, Paranjay Goel, Shubhani Aggarwal, Rajat Chaudhary, Ishan Budhiraja · 2024

Cross-Site Request Forgery (CSRF) remains a pervasive vulnerability in web applications, appearing regularly in the OWASP Top 10 lists, posing significant threats to user data and system integrity despite the existence of numerous rectification methodologies. This study undertakes a thorough, comprehensive analysis of the present environment of CSRF prevention systems, investigating their operational mechanisms, effectiveness, and associated limitations. Hence, this paper explores the role of CSRF tokens in the prevention of cyberattacks, including the detection of token absence and the implementation of token-based countermeasures to mitigate CSRF risks. The system model utilizing simple JavaScript and Flask Applications that aim to utilize the token-based countermeasure to identify the existence of tokens and generate and append them to requests, which ensures security of user data and system integrity.

Read the paper · More papers on PaperTik