SecurityBackend
CSRF
Also written as Cross-Site Request Forgery
A vulnerability where an attacker tricks a logged-in user's browser into submitting an unwanted request (like a money transfer) to a site the user is authenticated on.
Think of it like
Like someone slipping a pre-signed authorization form into a stack of papers you're already signing, so you approve something without meaning to.
Junior or senior?
Junior sounds like
Confuses CSRF with XSS.
Senior sounds like
Can clearly distinguish the two and describe how their team defended against each.
Ask them
“What's the difference between XSS and CSRF, and how did your team defend against each?”