VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 191 of 482
  • CVE-2022-42078MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.

  • CVE-2022-42077MedOct 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.

  • CVE-2022-3208MedOct 10, 2022
    risk 0.42cvss 6.5epss 0.00

    The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.

  • CVE-2022-3057MedSep 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-29823MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465.

  • CVE-2021-20468MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.

  • CVE-2020-4301MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176609.

  • CVE-2021-39394MedAug 26, 2022
    risk 0.42cvss 6.5epss 0.00

    mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add user accounts and modify user information.

  • CVE-2022-2555MedAug 22, 2022
    risk 0.42cvss 6.5epss 0.00

    The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which could allow attacker to make a logged in admin change them via a CSRF attack.

  • CVE-2022-2388MedAug 22, 2022
    risk 0.42cvss 6.5epss 0.00

    The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, which could allow attackers to make a logged in admin delete arbitrary ones via a CSRF attack

  • CVE-2022-2355MedAug 8, 2022
    risk 0.42cvss 6.5epss 0.00

    The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin

  • CVE-2022-2260MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.00

    The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve…

  • CVE-2022-36911MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specified URL.

  • CVE-2022-36908MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller…

  • CVE-2022-36906MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.

  • CVE-2022-22686MedJul 26, 2022
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.

  • CVE-2022-22359MedJul 19, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.

  • CVE-2021-38868MedJul 18, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.

  • CVE-2022-2091MedJul 11, 2022
    risk 0.42cvss 6.5epss 0.01

    The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.

  • CVE-2022-1732MedJul 11, 2022
    risk 0.42cvss 6.5epss 0.01

    The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attackers to make a logged in admin change them via a CSRF attack