Cross-Site Request Forgery (CSRF) Protection On POST Requests On Non-Setup Pages Is Disabled

< 1 min read

Impact Area

Security

Severity

Warning

Affected Element

Org Config

Rule ID #

SF-0158

Impact #

Increased vulnerability to Cross-Site Request Forgery (CSRF) attacks.

Remediation #

Enable this setting as described in this Salesforce knowledgebase article.

Time to fix #

30 min

References #

This rule is linked to Common Weakness Enumeration CWE-352 Cross-Site Request Forgery (CSRF).

Updated on March 21, 2025
Was it helpful ?