VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 115 of 482
  • CVE-2021-24905HigMar 21, 2022
    risk 0.52cvss 8.0epss 0.01

    The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server.…

  • CVE-2021-4030HigFeb 24, 2022
    risk 0.52cvss 8.0epss 0.00

    A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.

  • CVE-2021-24936HigJan 24, 2022
    risk 0.52cvss 8.0epss 0.01

    The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

  • CVE-2020-20593HigDec 22, 2021
    risk 0.52cvss 8.0epss 0.00

    A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.

  • CVE-2021-24945HigDec 13, 2021
    risk 0.52cvss 8.0epss 0.01

    The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked…

  • CVE-2021-24914HigDec 6, 2021
    risk 0.52cvss 8.0epss 0.01

    The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple subscribers) to change the…

  • CVE-2021-42097HigOct 21, 2021
    risk 0.52cvss 8.0epss 0.01

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for…

  • CVE-2021-20758HigAug 18, 2021
    risk 0.52cvss 8.0epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unspecified vectors.

  • CVE-2020-18458HigAug 12, 2021
    risk 0.52cvss 8.0epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.

  • CVE-2021-21407HigJul 21, 2021
    risk 0.52cvss 8.0epss 0.00

    Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop portal via a tricky browser procedure. The vulnerability is patched in version 2.7.4 and 3.0.0.

  • CVE-2020-22000HigApr 27, 2021
    risk 0.52cvss 8.0epss 0.01

    HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a CSRF vulnerability to execute arbitrary shell commands as the web user via the 'set_command_on' and 'set_command_off' POST…

  • CVE-2020-28403HigJan 29, 2021
    risk 0.52cvss 8.0epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account…

  • CVE-2020-35273HigDec 21, 2020
    risk 0.52cvss 8.0epss 0.01

    EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.

  • CVE-2020-13658HigSep 30, 2020
    risk 0.52cvss 8.0epss 0.00

    In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.

  • CVE-2020-2196HigJun 3, 2020
    risk 0.52cvss 8.0epss 0.01

    Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.

  • CVE-2020-11069HigMay 14, 2020
    risk 0.52cvss 8.0epss 0.01

    In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that the backend user interface and install tool are vulnerable to a same-site request forgery. A backend user can be tricked into interacting with a malicious resource an attacker previously…

  • CVE-2017-18861HigApr 28, 2020
    risk 0.52cvss 8.0epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects ReadyNAS Surveillance 1.4.3-15-x86 and earlier and ReadyNAS Surveillance 1.1.4-5-ARM and earlier.

  • CVE-2018-21120HigApr 22, 2020
    risk 0.52cvss 8.0epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7,…

  • CVE-2017-8334HigJun 18, 2019
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does not implement any cross-site scripting…

  • CVE-2019-9062HigFeb 23, 2019
    risk 0.52cvss 8.0epss 0.01

    PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.