VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 109 of 482
  • CVE-2024-2232HigAug 5, 2024
    risk 0.53cvss 8.1epss 0.00

    The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

  • CVE-2024-3983HigAug 1, 2024
    risk 0.53cvss 8.1epss 0.00

    The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

  • CVE-2024-5167HigJul 13, 2024
    risk 0.53cvss 8.1epss 0.00

    The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist…

  • CVE-2024-5712HigJun 28, 2024
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in the context of a victim's browser, such as deleting projects or changing…

  • CVE-2024-4757HigJun 25, 2024
    risk 0.53cvss 8.1epss 0.00

    The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2024-4328HigJun 10, 2024
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows…

  • CVE-2024-33830HigMay 6, 2024
    risk 0.53cvss 8.1epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

  • CVE-2024-24336HigMar 19, 2024
    risk 0.53cvss 8.1epss 0.00

    A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized…

  • CVE-2024-26469HigMar 3, 2024
    risk 0.53cvss 8.1epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url parameter in the postProcess() method.

  • CVE-2024-20255HigFeb 7, 2024
    risk 0.53cvss 8.2epss 0.01

    A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient…

  • CVE-2022-3899HigJan 16, 2024
    risk 0.53cvss 8.1epss 0.00

    The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by…

  • CVE-2023-6689HigDec 20, 2023
    risk 0.53cvss 8.2epss 0.00

    A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise the entire web application.

  • CVE-2023-50774HigDec 13, 2023
    risk 0.53cvss 8.1epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system.

  • CVE-2023-38130HigNov 17, 2023
    risk 0.53cvss 8.1epss 0.00

    Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.

  • CVE-2023-43148HigOct 12, 2023
    risk 0.53cvss 8.1epss 0.00

    SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.

  • CVE-2023-39372HigSep 3, 2023
    risk 0.53cvss 8.1epss 0.00

    StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)

  • CVE-2023-32761HigJul 14, 2023
    risk 0.53cvss 8.1epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.

  • CVE-2023-37597HigJul 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete user grouplist function.

  • CVE-2023-37596HigJul 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.

  • CVE-2023-36690HigJul 11, 2023
    risk 0.53cvss 8.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.