VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 188 of 482
  • CVE-2023-36256MedJul 7, 2023
    risk 0.42cvss 6.5epss 0.00

    The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the…

  • CVE-2023-37131MedJul 6, 2023
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.

  • CVE-2020-20502MedJun 20, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.

  • CVE-2023-35148MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

  • CVE-2023-33409MedJun 5, 2023
    risk 0.42cvss 6.5epss 0.00

    Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.

  • CVE-2023-33314MedMay 28, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.

  • CVE-2023-2736HigMay 20, 2023
    risk 0.42cvss 7.5epss 0.00

    The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation in the 'ajax_edit_contact' function. This makes it possible for authenticated attackers to receive the auto login…

  • CVE-2023-28361MedMay 11, 2023
    risk 0.42cvss 6.5epss 0.00

    A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR…

  • CVE-2023-0522MedMay 8, 2023
    risk 0.42cvss 6.5epss 0.00

    The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2020-22334MedMay 8, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /admin/admin_admin.php.

  • CVE-2022-40724MedApr 25, 2023
    risk 0.42cvss 6.4epss 0.00

    The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.

  • CVE-2023-26841MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.

  • CVE-2023-27520MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the…

  • CVE-2023-20130MedApr 5, 2023
    risk 0.42cvss 6.5epss 0.00

    Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-site request forgery…

  • CVE-2023-1330MedApr 3, 2023
    risk 0.42cvss 6.5epss 0.00

    The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

  • CVE-2023-0336MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.

  • CVE-2023-0335MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

  • CVE-2023-20113MedMar 23, 2023
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the…

  • CVE-2023-27234MedMar 15, 2023
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes within the application.

  • CVE-2023-27073MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.