Common Weakness Enumeration

    CWE Definition / CWE-293

    CWE-293: Using Referer Field for Authentication

    The referer field in HTTP requests can be easily modified and, as such, is not a valid means of message integrity checking.

    Published:19 Jul 2006
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-290: Authentication Bypass by Spoofing