VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 112 of 482
  • CVE-2019-6319HigJan 9, 2020
    risk 0.53cvss 8.1epss 0.01

    HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device…

  • CVE-2019-6320HigJan 9, 2020
    risk 0.53cvss 8.1epss 0.01

    Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device…

  • CVE-2019-13930HigDec 12, 2019
    risk 0.53cvss 8.1epss 0.00

    A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate…

  • CVE-2013-6364HigNov 5, 2019
    risk 0.53cvss 8.8epss 0.02

    Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

  • CVE-2015-9455HigOct 7, 2019
    risk 0.53cvss 8.1epss 0.01

    The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.

  • CVE-2019-16531HigSep 20, 2019
    risk 0.53cvss 8.8epss 0.03

    LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.

  • CVE-2019-14526HigAug 14, 2019
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web…

  • CVE-2018-10899HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.03

    A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

  • CVE-2019-14240HigJul 23, 2019
    risk 0.53cvss 8.1epss 0.01

    WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.

  • CVE-2019-7746HigMay 7, 2019
    risk 0.53cvss 8.1epss 0.01

    JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to change the Wi-Fi password or perform a factory reset.

  • CVE-2019-1713HigMay 3, 2019
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2019-1764HigMar 22, 2019
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF…

  • CVE-2019-6779HigJan 24, 2019
    risk 0.53cvss 8.1epss 0.00

    Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.

  • CVE-2018-1002103HigDec 5, 2018
    risk 0.53cvss 8.1epss 0.01

    In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebinding to indirectly make requests to the Kubernetes Dashboard, create a new…

  • CVE-2014-6046HigAug 28, 2018
    risk 0.53cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) delete active users by leveraging improper validation of CSRF tokens or that (2) delete open…

  • CVE-2018-14057HigAug 17, 2018
    risk 0.53cvss 8.8epss 0.03

    Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.

  • CVE-2017-9963HigFeb 12, 2018
    risk 0.53cvss 8.1epss 0.00

    A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type…

  • CVE-2017-16244HigNov 1, 2017
    risk 0.53cvss 8.8epss 0.02

    Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and…

  • CVE-2017-15735HigOct 22, 2017
    risk 0.53cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

  • CVE-2017-15734HigOct 22, 2017
    risk 0.53cvss 8.8epss 0.01

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.