VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 185 of 482
  • CVE-2023-38001MedJul 30, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 260206.

  • CVE-2024-6230MedJul 30, 2024
    risk 0.42cvss 6.5epss 0.00

    The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

  • CVE-2024-6490MedJul 26, 2024
    risk 0.42cvss 6.5epss 0.00

    During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

  • CVE-2024-5815MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is that the attacker would have to be a trusted GitHub Enterprise Server user, and the victim…

  • CVE-2024-5028MedJul 13, 2024
    risk 0.42cvss 6.5epss 0.00

    The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-40601MedJul 7, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.

  • CVE-2024-27717MedJul 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token Handling component.

  • CVE-2021-45785MedJun 24, 2024
    risk 0.42cvss 6.5epss 0.00

    TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart…

  • CVE-2024-4382MedJun 21, 2024
    risk 0.42cvss 6.5epss 0.00

    The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

  • CVE-2024-31612MedJun 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator information.

  • CVE-2024-5786MedJun 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an attacker to force an end user to execute unwanted actions in a web application to which he is authenticated.

  • CVE-2024-4218MedMay 30, 2024
    risk 0.42cvss 6.5epss 0.00

    The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to plugin improperly releasing the tagged and patched version of the plugin - the vulnerable version is used as the core files, while the…

  • CVE-2024-4532MedMay 27, 2024
    risk 0.42cvss 6.4epss 0.00

    The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks

  • CVE-2024-35475MedMay 22, 2024
    risk 0.42cvss 6.4epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL…

  • CVE-2024-34958MedMay 16, 2024
    risk 0.42cvss 6.5epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add

  • CVE-2024-35109MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close.

  • CVE-2024-32712HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.00

    Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.

  • CVE-2024-1756MedApr 24, 2024
    risk 0.42cvss 6.5epss 0.00

    The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name

  • CVE-2024-32538MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Joshua Eldridge Easy CountDowner allows Stored XSS.This issue affects Easy CountDowner: from n/a through 1.0.8.

  • CVE-2024-32091MedApr 15, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Tonjoo Sangar Slider.This issue affects Sangar Slider: from n/a through 1.3.2.