CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 173 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15151 | Hig | 0.45 | 8.0 | 0.01 | Aug 20, 2020 | OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6… | ||
| CVE-2020-15600 | Med | 0.45 | 6.5 | 0.02 | Jul 7, 2020 | An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password. | ||
| CVE-2020-8505 | Med | 0.45 | 6.5 | 0.01 | Jan 31, 2020 | School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user. | ||
| CVE-2020-8504 | Med | 0.45 | 6.5 | 0.01 | Jan 31, 2020 | School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user. | ||
| CVE-2020-8425 | Med | 0.45 | 6.5 | 0.01 | Jan 28, 2020 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php. | ||
| CVE-2013-4865 | Med | 0.45 | 6.5 | 0.02 | Jan 28, 2020 | Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter. | ||
| CVE-2015-5595 | Med | 0.45 | 6.5 | 0.01 | Dec 31, 2019 | Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption). | ||
| CVE-2013-4665 | Med | 0.45 | 6.5 | 0.01 | Dec 27, 2019 | SPBAS Business Automation Software 2012 has CSRF. | ||
| CVE-2012-4385 | Med | 0.45 | 6.5 | 0.02 | Nov 13, 2019 | letodms 3.3.6 has CSRF via change password | ||
| CVE-2019-8109 | Hig | 0.45 | 8.0 | 0.01 | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution. | ||
| CVE-2013-6275 | Med | 0.45 | 6.5 | 0.02 | Nov 5, 2019 | Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. | ||
| CVE-2019-15062 | Hig | 0.45 | 8.0 | 0.01 | Aug 14, 2019 | An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is… | ||
| CVE-2019-11375 | Med | 0.45 | 6.5 | 0.03 | Apr 20, 2019 | Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI. | ||
| CVE-2019-10300 | Hig | 0.45 | 8.0 | 0.01 | Apr 18, 2019 | A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through… | ||
| CVE-2019-7440 | Med | 0.45 | 6.5 | 0.02 | Mar 21, 2019 | JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi). | ||
| CVE-2018-17996 | Med | 0.45 | 6.5 | 0.03 | Mar 21, 2019 | LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/. | ||
| CVE-2018-19829 | Med | 0.45 | 6.5 | 0.02 | Dec 18, 2018 | Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known. | ||
| CVE-2018-18760 | Med | 0.45 | 6.5 | 0.03 | Nov 16, 2018 | RhinOS 3.0 build 1190 allows CSRF. | ||
| CVE-2018-11502 | Med | 0.45 | 6.5 | 0.02 | Aug 24, 2018 | An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF. | ||
| CVE-2018-7701 | Med | 0.45 | 6.5 | 0.03 | Mar 15, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) delete e-mail messages via a delete action in a request to secmail/getmessage.exe or (2)… |
- risk 0.45cvss 8.0epss 0.01
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6…
- risk 0.45cvss 6.5epss 0.02
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
- risk 0.45cvss 6.5epss 0.01
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
- risk 0.45cvss 6.5epss 0.01
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.
- risk 0.45cvss 6.5epss 0.01
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
- risk 0.45cvss 6.5epss 0.02
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
- risk 0.45cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).
- risk 0.45cvss 6.5epss 0.01
SPBAS Business Automation Software 2012 has CSRF.
- risk 0.45cvss 6.5epss 0.02
letodms 3.3.6 has CSRF via change password
- risk 0.45cvss 8.0epss 0.01
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.
- risk 0.45cvss 6.5epss 0.02
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
- risk 0.45cvss 8.0epss 0.01
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is…
- risk 0.45cvss 6.5epss 0.03
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
- risk 0.45cvss 8.0epss 0.01
A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through…
- risk 0.45cvss 6.5epss 0.02
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).
- risk 0.45cvss 6.5epss 0.03
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.
- risk 0.45cvss 6.5epss 0.02
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.
- risk 0.45cvss 6.5epss 0.03
RhinOS 3.0 build 1190 allows CSRF.
- risk 0.45cvss 6.5epss 0.02
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF.
- risk 0.45cvss 6.5epss 0.03
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) delete e-mail messages via a delete action in a request to secmail/getmessage.exe or (2)…