Question 1
An authenticated user visits an unrelated website. A hidden form there submits a profile-change request to the user's account on another service, and the browser automatically includes that service's session cookie. The change succeeds without the user's approval. Investigation finds no injected script on the account service and no copied cookie. Which attack best fits this evidence?
Show answer & explanation
Correct answer: C - Cross-site request forgery using the browser's existing authenticated session.