VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 125 of 482
  • CVE-2016-10766HigJul 29, 2019
    risk 0.50cvss 8.8epss 0.01

    edx-platform before 2016-06-06 allows CSRF.

  • CVE-2019-13594HigJul 14, 2019
    risk 0.50cvss 8.8epss 0.01

    In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.

  • CVE-2019-10340HigJul 11, 2019
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another…

  • CVE-2015-9284HigApr 26, 2019
    risk 0.50cvss 8.8epss 0.02

    The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary…

  • CVE-2019-10642HigApr 17, 2019
    risk 0.50cvss 8.8epss 0.01

    Contao 4.7 allows CSRF.

  • CVE-2017-18366HigApr 15, 2019
    risk 0.50cvss 8.8epss 0.01

    Subrion CMS 4.1.5 has CSRF in blog/delete/.

  • CVE-2017-17835HigJan 23, 2019
    risk 0.50cvss 8.8epss 0.02

    In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.

  • CVE-2018-20595HigDec 30, 2018
    risk 0.50cvss 8.8epss 0.01

    A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.

  • CVE-2018-14603HigJul 27, 2018
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in the Test feature of the System Hooks component.

  • CVE-2018-12540HigJul 12, 2018
    risk 0.50cvss 8.8epss 0.02

    In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.

  • CVE-2018-11349HigJul 7, 2018
    risk 0.50cvss 8.8epss 0.01

    The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and search_link.

  • CVE-2016-10522HigJul 5, 2018
    risk 0.50cvss 8.8epss 0.01

    rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.

  • CVE-2018-11406HigJun 13, 2018
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled…

  • CVE-2014-0594HigJun 8, 2018
    risk 0.50cvss 8.8epss 0.01

    In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.

  • CVE-2018-9856HigApr 9, 2018
    risk 0.50cvss 8.8epss 0.01

    Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-document/@@share request.

  • CVE-2018-1098HigApr 3, 2018
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST…

  • CVE-2018-8764HigMar 27, 2018
    risk 0.50cvss 8.8epss 0.01

    Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

  • CVE-2018-1000086HigMar 13, 2018
    risk 0.50cvss 8.8epss 0.01

    NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function. https://github.com/nprapps/pym.js/blob/master/src/pym.js#L573 that can result in Arbitrary javascript code execution.…

  • CVE-2018-7634HigMar 1, 2018
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functionality by attackers. By making a CSRF attack, an attacker could make a victim change his registered e-mail address on the…

  • CVE-2018-6009HigJan 22, 2018
    risk 0.50cvss 8.8epss 0.01

    In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.