VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 173 of 482
  • CVE-2020-15151HigAug 20, 2020
    risk 0.45cvss 8.0epss 0.01

    OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6…

  • CVE-2020-15600MedJul 7, 2020
    risk 0.45cvss 6.5epss 0.02

    An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.

  • CVE-2020-8505MedJan 31, 2020
    risk 0.45cvss 6.5epss 0.01

    School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.

  • CVE-2020-8504MedJan 31, 2020
    risk 0.45cvss 6.5epss 0.01

    School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.

  • CVE-2020-8425MedJan 28, 2020
    risk 0.45cvss 6.5epss 0.01

    Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.

  • CVE-2013-4865MedJan 28, 2020
    risk 0.45cvss 6.5epss 0.02

    Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.

  • CVE-2015-5595MedDec 31, 2019
    risk 0.45cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).

  • CVE-2013-4665MedDec 27, 2019
    risk 0.45cvss 6.5epss 0.01

    SPBAS Business Automation Software 2012 has CSRF.

  • CVE-2012-4385MedNov 13, 2019
    risk 0.45cvss 6.5epss 0.02

    letodms 3.3.6 has CSRF via change password

  • CVE-2019-8109HigNov 5, 2019
    risk 0.45cvss 8.0epss 0.01

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.

  • CVE-2013-6275MedNov 5, 2019
    risk 0.45cvss 6.5epss 0.02

    Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

  • CVE-2019-15062HigAug 14, 2019
    risk 0.45cvss 8.0epss 0.01

    An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is…

  • CVE-2019-11375MedApr 20, 2019
    risk 0.45cvss 6.5epss 0.03

    Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.

  • CVE-2019-10300HigApr 18, 2019
    risk 0.45cvss 8.0epss 0.01

    A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through…

  • CVE-2019-7440MedMar 21, 2019
    risk 0.45cvss 6.5epss 0.02

    JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).

  • CVE-2018-17996MedMar 21, 2019
    risk 0.45cvss 6.5epss 0.03

    LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.

  • CVE-2018-19829MedDec 18, 2018
    risk 0.45cvss 6.5epss 0.02

    Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.

  • CVE-2018-18760MedNov 16, 2018
    risk 0.45cvss 6.5epss 0.03

    RhinOS 3.0 build 1190 allows CSRF.

  • CVE-2018-11502MedAug 24, 2018
    risk 0.45cvss 6.5epss 0.02

    An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF.

  • CVE-2018-7701MedMar 15, 2018
    risk 0.45cvss 6.5epss 0.03

    Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) delete e-mail messages via a delete action in a request to secmail/getmessage.exe or (2)…