VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 194 of 482
  • CVE-2022-28921MedMay 18, 2022
    risk 0.42cvss 6.5epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.

  • CVE-2022-1407MedMay 16, 2022
    risk 0.42cvss 6.5epss 0.01

    The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking…

  • CVE-2022-0191MedMay 2, 2022
    risk 0.42cvss 6.5epss 0.01

    The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans

  • CVE-2022-27375MedApr 25, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.

  • CVE-2022-27374MedApr 25, 2022
    risk 0.42cvss 6.5epss 0.00

    Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.

  • CVE-2022-23975MedApr 18, 2022
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any installed plugin.

  • CVE-2022-20735MedApr 15, 2022
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the…

  • CVE-2022-26589MedApr 13, 2022
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.

  • CVE-2022-0914MedApr 11, 2022
    risk 0.42cvss 6.5epss 0.01

    The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and…

  • CVE-2022-26588MedApr 8, 2022
    risk 0.42cvss 6.5epss 0.01

    A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.

  • CVE-2022-0830MedApr 4, 2022
    risk 0.42cvss 6.5epss 0.01

    The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a…

  • CVE-2022-28143MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins…

  • CVE-2021-43737MedMar 23, 2022
    risk 0.42cvss 6.5epss 0.00

    An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.

  • CVE-2022-0681MedMar 21, 2022
    risk 0.42cvss 6.5epss 0.01

    The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack

  • CVE-2022-27210MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2022-0445MedMar 7, 2022
    risk 0.42cvss 6.5epss 0.01

    The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack

  • CVE-2021-25098MedMar 7, 2022
    risk 0.42cvss 6.5epss 0.01

    The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, which will be put in the trash

  • CVE-2022-23052MedMar 3, 2022
    risk 0.42cvss 6.5epss 0.00

    PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application.

  • CVE-2021-25081MedFeb 28, 2022
    risk 0.42cvss 6.5epss 0.01

    The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

  • CVE-2021-45007MedFeb 20, 2022
    risk 0.42cvss 6.5epss 0.01

    Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users