Home › Forums › Why can’t someone scrape a CSRF token from a website to circumvent CSRF protection? › Reply To: Why can’t someone scrape a CSRF token from a website to circumvent CSRF protection?
February 7, 2021 at 4:36 am
#359977
__lt__
Because CSRF tokens are generated for each session, sometimes for each web form. The token you can get is for your session/form only.
Comments