VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 196 of 482
  • CVE-2021-24852MedNov 17, 2021
    risk 0.42cvss 6.5epss 0.01

    The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2021-24802MedNov 17, 2021
    risk 0.42cvss 6.5epss 0.01

    The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack

  • CVE-2020-28137MedNov 10, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router.

  • CVE-2021-40518MedNov 10, 2021
    risk 0.42cvss 6.5epss 0.00

    Airangel HSMX Gateway devices through 5.2.04 allow CSRF.

  • CVE-2021-24767MedNov 8, 2021
    risk 0.42cvss 6.5epss 0.01

    The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack

  • CVE-2021-24766MedNov 8, 2021
    risk 0.42cvss 6.5epss 0.01

    The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attack

  • CVE-2021-24674MedNov 8, 2021
    risk 0.42cvss 6.5epss 0.01

    The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack

  • CVE-2021-22051MedNov 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.5+, 2.2.x users should upgrade to…

  • CVE-2020-21139MedNov 4, 2021
    risk 0.42cvss 6.5epss 0.00

    EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.

  • CVE-2021-34773MedNov 4, 2021
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P)…

  • CVE-2020-36505MedNov 1, 2021
    risk 0.42cvss 6.5epss 0.01

    The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

  • CVE-2020-36504MedNov 1, 2021
    risk 0.42cvss 6.5epss 0.01

    The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog

  • CVE-2021-24779MedOct 25, 2021
    risk 0.42cvss 6.5epss 0.01

    The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users.

  • CVE-2021-39126MedOct 21, 2021
    risk 0.42cvss 6.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in the referrer headers which discloses a user's CSRF token. The…

  • CVE-2021-24735MedOct 18, 2021
    risk 0.42cvss 6.5epss 0.01

    The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

  • CVE-2021-24675MedOct 18, 2021
    risk 0.42cvss 6.5epss 0.01

    The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack

  • CVE-2021-24642MedOct 18, 2021
    risk 0.42cvss 6.5epss 0.01

    The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as…

  • CVE-2021-24595MedOct 18, 2021
    risk 0.42cvss 6.5epss 0.01

    The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a…

  • CVE-2021-39864MedOct 15, 2021
    risk 0.42cvss 6.5epss 0.02

    Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an…

  • CVE-2020-19964MedOct 14, 2021
    risk 0.42cvss 6.5epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.