> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# Performing CSRF exploits over GraphQL

> PortSwigger Web Security Academy lab: Performing CSRF exploits over GraphQL. Tema: GraphQL.

# Performing CSRF exploits over GraphQL

<p className="machine-summary"><span className="prompt"><code>\$ tldr</code></span> PortSwigger · GraphQL</p>

<div className="machine-meta">
  | ·           | ·                                                                                      |
  | ----------- | -------------------------------------------------------------------------------------- |
  | Plataforma  | PortSwigger Web Security Academy                                                       |
  | Tema        | GraphQL                                                                                |
  | Dificultad  | <span className="dbadge dbadge-medium">PRACTITIONER</span>                             |
  | Lab oficial | [Abrir](https://portswigger.net/web-security/graphql/lab-graphql-csrf-via-graphql-api) |
</div>

## Resolver el lab

| Idioma  | Autor           | Formato | Enlace                                                                                 |
| ------- | --------------- | ------- | -------------------------------------------------------------------------------------- |
| 🇬🇧 EN | **PortSwigger** | Texto   | [Abrir](https://portswigger.net/web-security/graphql/lab-graphql-csrf-via-graphql-api) |

## Recursos por skill

| Skill                             | Fuente      | Enlace                                                |
| --------------------------------- | ----------- | ----------------------------------------------------- |
| GraphQL Vulnerabilities           | PortSwigger | [Abrir](https://portswigger.net/web-security/graphql) |
| CSRF (Cross-Site Request Forgery) | PortSwigger | [Abrir](https://portswigger.net/web-security/csrf)    |

## Skills relacionadas

[GraphQL Vulnerabilities](/skills/graphql) · [CSRF (Cross-Site Request Forgery)](/skills/csrf)

***

## Comentarios y truquillos

¿Has resuelto el lab por una vía distinta? Compártela aquí — los comentarios viven en [GitHub Discussions](https://github.com/FFuson/HTB_Writeups/discussions).

<div className="rootea-giscus-wrap" data-giscus-term="lab:graphql-graphql-csrf-via-graphql-api" data-giscus-lang="es" />

*Última actualización: 2026-05-08*

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"TechArticle","name":"Performing CSRF exploits over GraphQL","headline":"Performing CSRF exploits over GraphQL — PortSwigger lab index","url":"https://rootea.es/portswigger/labs/graphql/graphql-csrf-via-graphql-api","inLanguage":"es","about":[{"@type":"Thing","name":"PortSwigger Web Security Academy"},{"@type":"Thing","name":"GraphQL"}],"isPartOf":{"@type":"WebSite","name":"rootea.es","url":"https://rootea.es"},"author":{"@type":"Organization","name":"rootea.es"}}`}
</script>
