The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CSRF issue

David | Last updated: Mar 16, 2023 05:01PM UTC

When I run Burp Suite scanner on my website I get the following issue on many pages. "The request appears to be vulnerable to cross-site request forgery (CSRF) attacks against authenticated users." These pages have no forms or inputs on them so I am trying to understand what is triggering this issue. Comparing the 2 responses (the one with the valid referrer domain and the one with the bogus referrer domain) they look the same.

Michelle, PortSwigger Agent | Last updated: Mar 17, 2023 12:17PM UTC