CWE-293: Using Referer Field for Authentication

VariantDraftExploit Likelihood: High

The referer field in HTTP requests can be easily modified and, as such, is not a valid means of message integrity checking.

View on MITRE
Back to CWE Lookup

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms

Learn More