SecurityBackend

CSRF

Also written as Cross-Site Request Forgery

A vulnerability where an attacker tricks a logged-in user's browser into submitting an unwanted request (like a money transfer) to a site the user is authenticated on.

Think of it like

Like someone slipping a pre-signed authorization form into a stack of papers you're already signing, so you approve something without meaning to.

Junior or senior?

Junior sounds like

Confuses CSRF with XSS.

Senior sounds like

Can clearly distinguish the two and describe how their team defended against each.

Ask them

“What's the difference between XSS and CSRF, and how did your team defend against each?”