Payments are experiencing issues due to temporary restrictions in Russia. If your payment does not go through, please submit a support request.Our support team is available 24/7 — we are always here to help with hosting and server issues.We are now accepting requests for dedicated server rental and colocation services in our data center.Reminder: we recommend enabling backups for additional data protection.A new VPS/VDS lineup with NVMe storage and improved performance is now available.Maintenance work on some servers has been completed. All services are operating normally.

MODULE FOR 1C-BITRIX

Digital Element

Form Protection

Web application vulnerabilities are architectural flaws that allow attackers to disrupt service operations or access users' personal data. A primary category of such vulnerabilities is Cross-Site Request Forgery (CSRF).

Technical details

Published
25 September 2023
Updated
10 April 2026
Version
1.1.1
Installed
Fewer than 50 times
Compatible editions
First Site, Start, Standard, Small Business, Business, Online store + CRM
Responsive design
Yes
Composite support
Yes
Compatible with Sites24
No
Developer
Digital Element

What this solution does

Web application vulnerabilities are architectural flaws that allow attackers to disrupt service operations or access users' personal data.

A primary category of such vulnerabilities is Cross-Site Request Forgery (CSRF). This attack exploits specific characteristics of the HTTP protocol: if a user's browser is induced to send a request to a vulnerable server, it will automatically include the user's current cookies in that request.

In a successful CSRF attack, a victim visiting a malicious site unknowingly triggers harmful actions on another server, such as transferring funds to an attacker's account. For this to occur, the user must be authenticated on the target server, and the request must not require any user confirmation that cannot be bypassed or forged by the attacking script.

The delement.csrf module enhances form protection across all editions of 1C-Bitrix. A short-lived CSRF token is generated for each form and verified upon submission. Unlike the standard bx_sessid check, this token is bound to a specific form and has a limited validity period, minimizing risks even if the token is intercepted.

The solution protects against cross-site request forgery. Even if an attacker uses the user's current cookies, they cannot access the required token to submit forms on the user's behalf.

Connecting a form from the Web Forms module

Enable form validation in the module settings.

Set a unique secret for code generation.

Specify the desired token lifetime in seconds.

Select the required form from the list.

Add an input field with the token to the form template using the DelementCsrfHelper::getCsrfInput method, passing the WEB_FORM_ID parameter.

Connecting to custom forms

Insert an input field with the token into your form. Generate the token using the DelementCsrfHelper::getCsrf method by passing a unique form identifier.

Add token validation in the form processing script using the DelementCsrfHelper::validateCsrf method, passing the same unique form identifier.

If “Form Protection” is required, General iT can help with installation, configuration and a technical check after integration.

UPDATE HISTORY

What’s new

1 releases
1.1.1 (09.04.2026)Latest update

Fixed work with composite site

USER EXPERIENCE

Solution reviews

How does this solution work in a real project? Share your experience and help others choose.

Be the first to share your experience

There are no reviews of this solution on git.ru yet. Tell us what worked well and what could be improved.

Verified purchaseAdd a key if you wish. A verified review gets a badge, priority placement and more rating weight.

Open to every clientJust sign in to your account. A key is optional; all reviews are moderated.

YOUR EXPERIENCE MATTERS

Your review

YOUR PROJECT INFRASTRUCTURE

A home for your website

BEFORE YOU ORDER

Let’s go through the details.

What does the price cover?
The displayed price covers the solution itself. Platform licensing, installation and customisation are checked separately. If the page offers bundles, select the required option before submitting a request.
How do I check compatibility?
Compare the supported editions and solution version in the technical details with your project. Before installing on a live website, we recommend making a backup and checking the solution in a test environment.
How much does this solution’s renewal cost?
The current renewal price is 2,450 ₽. Before you order, a manager will confirm the renewal period and whether it applies to your licence.
Can you help with implementation?
We can help install the module, check its settings and verify how it works in your project. Compatibility with other customisations and the scope of work are assessed before we begin.

GENERAL iT

Let’s discuss your project

Получатель: ООО «Дженерал Ай Ти Рус»

1C-BITRIX

Install solution

Enter a domain with or without https://. The installer will open in your website control panel in a new tab.

Solution screenshots

Solution screenshot