VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 190 of 482
  • CVE-2022-45673MedDec 2, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-44937MedNov 28, 2022
    risk 0.42cvss 6.5epss 0.00

    Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.

  • CVE-2020-23590MedNov 23, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack to change the Password for "WLAN SSID" through "wlwpa.asp".

  • CVE-2020-23589MedNov 23, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through "…

  • CVE-2020-23593MedNov 23, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events,…

  • CVE-2022-44737MedNov 22, 2022
    risk 0.42cvss 6.5epss 0.00

    Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.

  • CVE-2020-23582MedNov 21, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID.

  • CVE-2022-44389MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.

  • CVE-2022-3632MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.00

    The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions.

  • CVE-2022-3538MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.00

    The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenticated users to disable arbitrary plugins

  • CVE-2022-2449MedNov 14, 2022
    risk 0.42cvss 6.5epss 0.00

    The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site.

  • CVE-2022-45130MedNov 10, 2022
    risk 0.42cvss 6.5epss 0.00

    Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of the Plesk product: version numbers were used through version 12, and then the convention was changed so that versions are…

  • CVE-2022-30694MedNov 8, 2022
    risk 0.42cvss 6.5epss 0.00

    The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.

  • CVE-2022-3419MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.00

    The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

  • CVE-2022-40488MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.00

    ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).

  • CVE-2022-2762MedOct 25, 2022
    risk 0.42cvss 6.5epss 0.00

    The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update their notes via a CSRF attack

  • CVE-2022-3082MedOct 17, 2022
    risk 0.42cvss 6.5epss 0.00

    The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example

  • CVE-2022-41474MedOct 13, 2022
    risk 0.42cvss 6.5epss 0.00

    RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any account.

  • CVE-2022-42087MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-42086MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.