VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 110 of 482
  • CVE-2023-27490HigMar 9, 2023
    risk 0.53cvss 8.1epss 0.01

    NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A bad actor who can read traffic on the victim's network or…

  • CVE-2022-47395HigJan 18, 2023
    risk 0.53cvss 8.1epss 0.00

    Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its monitor services. An attacker could take advantage of this vulnerability to execute arbitrary maintenance operations and cause a…

  • CVE-2022-45127HigJan 18, 2023
    risk 0.53cvss 8.1epss 0.00

    Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its backup services. An attacker could take advantage of this vulnerability to execute arbitrary backup operations and cause a…

  • CVE-2023-22286HigJan 17, 2023
    risk 0.53cvss 8.1epss 0.00

    Cross-site request forgery (CSRF) vulnerability in MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allows a remote unauthenticated attacker…

  • CVE-2023-22457CriJan 4, 2023
    risk 0.53cvss 9.0epss 0.19

    CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. If a…

  • CVE-2022-3999HigDec 12, 2022
    risk 0.53cvss 8.1epss 0.00

    The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.

  • CVE-2022-41489HigOct 13, 2022
    risk 0.53cvss 8.1epss 0.00

    WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack of authentication in the component Usb_upload.htm.

  • CVE-2022-40179HigOct 11, 2022
    risk 0.53cvss 8.1epss 0.00

    A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions <…

  • CVE-2022-1572HigJun 27, 2022
    risk 0.53cvss 8.1epss 0.01

    The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

  • CVE-2022-33121HigJun 24, 2022
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.

  • CVE-2022-1791HigJun 13, 2022
    risk 0.53cvss 8.1epss 0.01

    The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related…

  • CVE-2022-1779HigJun 13, 2022
    risk 0.53cvss 8.1epss 0.01

    The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

  • CVE-2022-23976HigApr 18, 2022
    risk 0.53cvss 8.1epss 0.00

    Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (posts / pages / media).

  • CVE-2022-0141HigApr 12, 2022
    risk 0.53cvss 8.1epss 0.00

    The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

  • CVE-2022-0229HigMar 21, 2022
    risk 0.53cvss 8.1epss 0.01

    The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options…

  • CVE-2021-24823HigFeb 28, 2022
    risk 0.53cvss 8.1epss 0.01

    The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

  • CVE-2022-22811HigFeb 9, 2022
    risk 0.53cvss 8.1epss 0.00

    A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and…

  • CVE-2021-24641HigNov 23, 2021
    risk 0.53cvss 8.1epss 0.01

    The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion

  • CVE-2021-41275CriNov 17, 2021
    risk 0.53cvss 9.3epss 0.01

    spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that…

  • CVE-2021-41274CriNov 17, 2021
    risk 0.53cvss 9.3epss 0.01

    solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend…