# Cross-Site Request Forgery
> Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated. CSRF attacks specifically target state-changing requests, not theft of data, since the attacker has no way to see the response to the forged request. - OWASP
## Summary
* [Methodology](#methodology)
* [Payloads](#payloads)
## Methodology
data:image/s3,"s3://crabby-images/297de/297dea3d233a2cda51beeef32036ce729b97d9c6" alt="CSRF_cheatsheet"
## Payloads
### HTML GET – Requiring User Interaction for Proof-of-Concept
```html
Click Me
```
### HTML GET (No User Interaction)
```html
```
### HTML POST – Requiring User Interaction for Proof-of-Concept
```html