CWE-293: Using Referer Field for Authentication
VariantDraftExploit Likelihood: High
The referer field in HTTP requests can be easily modified and, as such, is not a valid means of message integrity checking.
View on MITREBack to CWE Lookup
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific