Concept Flow - Cross-site request forgery (CSRF)
User logged into Site A
User visits malicious Site B
Site B sends hidden request to Site A
Browser sends request with User's cookies
Site A processes request as if from User
Unintended action happens on Site A
This flow shows how a user logged into one site can be tricked by another site to perform unwanted actions without their knowledge.