VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 193 of 482
  • CVE-2022-1630MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack

  • CVE-2022-1610MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-30328MedJun 16, 2022
    risk 0.42cvss 6.5epss 0.00

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and password of the interface.

  • CVE-2022-30327MedJun 16, 2022
    risk 0.42cvss 6.5epss 0.00

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the pre-shared key of the Wi-Fi router if the interface's IP address is known.

  • CVE-2022-31294MedJun 16, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.

  • CVE-2022-30931MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Employee Leaves Management System (ELMS) V 2.1 is vulnerable to Cross Site Request Forgery (CSRF) via /myprofile.php.

  • CVE-2022-1790MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1788MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for…

  • CVE-2022-1761MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.

  • CVE-2022-1694MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.

  • CVE-2022-1624MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1612MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1608MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1605MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.01

    The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users

  • CVE-2021-25116MedJun 13, 2022
    risk 0.42cvss 6.5epss 0.00

    The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary…

  • CVE-2022-30898MedJun 9, 2022
    risk 0.42cvss 6.5epss 0.01

    A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.

  • CVE-2022-1570MedJun 8, 2022
    risk 0.42cvss 6.5epss 0.00

    The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.

  • CVE-2022-1424MedJun 8, 2022
    risk 0.42cvss 6.5epss 0.01

    The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.

  • CVE-2022-1422MedJun 8, 2022
    risk 0.42cvss 6.5epss 0.01

    The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.

  • CVE-2022-22361MedMay 31, 2022
    risk 0.42cvss 6.5epss 0.00

    IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0…