How does a xsrf token cookie protect against csrf?

418 Views Asked by At

Wouldn't a malicious site be able to read the cookie using xss cookie stealing and put it in the header of an ajax request?

1

There are 1 best solutions below

0
Gabor Lengyel On

Of course, if the site is vulnerable to xss, it's also vulnerable to csrf, but that's the smaller issue then.

If there is no xss though, the attacker has no way to read the token due to the same origin policy.