VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 111 of 482
  • CVE-2020-20514HigSep 24, 2021
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/.html allows authenticated attackers to delete all users.

  • CVE-2021-24639HigSep 20, 2021
    risk 0.53cvss 8.1epss 0.01

    The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

  • CVE-2021-24636HigSep 20, 2021
    risk 0.53cvss 8.1epss 0.01

    The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link

  • CVE-2021-37725HigSep 7, 2021
    risk 0.53cvss 8.1epss 0.00

    A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15. Aruba has released patches for Aruba…

  • CVE-2021-38342HigAug 30, 2021
    risk 0.53cvss 8.1epss 0.00

    The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` actions, which allowed attackers to trash or permanently purge arbitrary posts as well as changing their status, reassigning their…

  • CVE-2020-24130HigAug 20, 2021
    risk 0.53cvss 8.1epss 0.00

    A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts.

  • CVE-2021-24500HigAug 9, 2021
    risk 0.53cvss 8.1epss 0.01

    Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site,…

  • CVE-2021-20096HigMay 25, 2021
    risk 0.53cvss 8.1epss 0.01

    Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

  • CVE-2021-21731HigApr 13, 2021
    risk 0.53cvss 8.1epss 0.00

    A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management page does not fully verify whether the request comes from a trusted user. The attacker could submit a malicious request to the affected device to delete the…

  • CVE-2021-24230HigApr 12, 2021
    risk 0.53cvss 8.1epss 0.01

    The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If exploited, this bug can be…

  • CVE-2020-29030HigMar 5, 2021
    risk 0.53cvss 8.1epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4.

  • CVE-2021-1227HigFeb 24, 2021
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected…

  • CVE-2020-12123HigOct 2, 2020
    risk 0.53cvss 8.1epss 0.00

    CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If a user is authenticated in the router portal, then this attack will work.

  • CVE-2020-4617HigSep 22, 2020
    risk 0.53cvss 8.1epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 184930.

  • CVE-2020-15789HigSep 9, 2020
    risk 0.53cvss 8.1epss 0.00

    A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by…

  • CVE-2020-19886HigAug 24, 2020
    risk 0.53cvss 8.1epss 0.00

    DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.

  • CVE-2020-15882HigJul 23, 2020
    risk 0.53cvss 8.1epss 0.01

    A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database.

  • CVE-2019-20390HigMay 15, 2020
    risk 0.53cvss 8.1epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate…

  • CVE-2020-7983HigMay 5, 2020
    risk 0.53cvss 8.1epss 0.01

    A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.

  • CVE-2020-1692HigFeb 17, 2020
    risk 0.53cvss 8.1epss 0.01

    Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.