CWE-293—Using Referer Field for Authentication
PUBLISHEDweakness recordHigh
released 2006-07-19 · last modified 2025-12-11
Metadata
Weakness Name
Using Referer Field for Authentication
Description
The referer field in HTTP requests can be easily modified and, as such, is not a valid means of message integrity checking.