Skip to main content

CSRF where token validation depends on request method

$ tldr PortSwigger · CSRF (Cross-Site Request Forgery)

Solve the lab

Resources by skill

CSRF (Cross-Site Request Forgery)

Comments & tips

Solved this lab a different way? Share it here — comments live in GitHub Discussions.
Last updated: 2026-06-07