VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 189 of 482
  • CVE-2021-4333MedMar 7, 2023
    risk 0.42cvss 6.5epss 0.00

    The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it possible for unauthenticated attackers to activate and…

  • CVE-2021-33396MedFeb 15, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php.

  • CVE-2022-47373MedFeb 15, 2023
    risk 0.42cvss 6.4epss 0.00

    Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vulnerability arises on the forget password functionality in which parameter username does not proper input validation/sanitization thus results in executing…

  • CVE-2022-4138MedFeb 13, 2023
    risk 0.42cvss 6.4epss 0.00

    A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all versions starting from 15.7 before 15.7.6, and all versions starting from 15.8 before 15.8.1. An attacker could take over a project if an Owner or Maintainer uploads…

  • CVE-2021-37234MedFeb 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.

  • CVE-2022-4548MedJan 23, 2023
    risk 0.42cvss 6.5epss 0.00

    The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

  • CVE-2023-22852MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.00

    Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.

  • CVE-2022-46491MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbitrarily add Administrator accounts.

  • CVE-2022-4024MedDec 19, 2022
    risk 0.42cvss 6.5epss 0.00

    The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

  • CVE-2022-46059MedDec 13, 2022
    risk 0.42cvss 6.5epss 0.00

    AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2022-3946MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.

  • CVE-2022-3883MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary…

  • CVE-2022-3882MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary…

  • CVE-2022-3880MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate…

  • CVE-2022-3879MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

  • CVE-2022-41296MedDec 12, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237210.

  • CVE-2022-3926MedDec 5, 2022
    risk 0.42cvss 6.5epss 0.00

    The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID

  • CVE-2022-45668MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-45667MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-45674MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.