VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 175 of 482
  • CVE-2024-42768MedAug 22, 2024
    risk 0.44cvss 6.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.

  • CVE-2024-32863MedAug 1, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

  • CVE-2024-5284MedJul 13, 2024
    risk 0.44cvss 6.8epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2024-5077MedJul 13, 2024
    risk 0.44cvss 6.8epss 0.00

    The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2024-3632MedJul 13, 2024
    risk 0.44cvss 6.8epss 0.00

    The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2024-39155MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.

  • CVE-2024-5676MedJun 19, 2024
    risk 0.44cvss 6.8epss 0.00

    The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and the use of the HTTP method `GET` to introduce changes in the system.

  • CVE-2023-49965MedApr 5, 2024
    risk 0.44cvss 6.8epss 0.00

    SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

  • CVE-2024-2322MedApr 3, 2024
    risk 0.44cvss 6.8epss 0.00

    The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF…

  • CVE-2024-1231MedMar 25, 2024
    risk 0.44cvss 6.8epss 0.00

    The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack

  • CVE-2024-21381MedFeb 13, 2024
    risk 0.44cvss 6.8epss 0.00

    Microsoft Azure Active Directory B2C Spoofing Vulnerability

  • CVE-2023-3589MedOct 9, 2023
    risk 0.44cvss 6.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.

  • CVE-2023-24518MedOct 3, 2023
    risk 0.44cvss 6.7epss 0.00

    A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.

  • CVE-2023-40048MedSep 27, 2023
    risk 0.44cvss 6.8epss 0.00

    In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function.

  • CVE-2020-18409MedJun 27, 2023
    risk 0.44cvss 6.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html.

  • CVE-2020-18416MedJun 27, 2023
    risk 0.44cvss 6.8epss 0.00

    An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment information.

  • CVE-2023-34839MedJun 27, 2023
    risk 0.44cvss 6.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.

  • CVE-2023-1965MedMay 3, 2023
    risk 0.44cvss 6.8epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to…

  • CVE-2022-46368MedJan 12, 2023
    risk 0.44cvss 6.8epss 0.00

    Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

  • CVE-2022-46367MedJan 12, 2023
    risk 0.44cvss 6.8epss 0.00

    Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.