VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 197 of 482
  • CVE-2020-21658MedOct 6, 2021
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL.

  • CVE-2021-31604MedSep 27, 2021
    risk 0.42cvss 6.5epss 0.01

    furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.

  • CVE-2021-29816MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204341.

  • CVE-2021-22950MedSep 23, 2021
    risk 0.42cvss 6.5epss 0.00

    Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"

  • CVE-2020-21081MedSep 14, 2021
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

  • CVE-2020-19264MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily add users via index.php?s=/user/ApiAdminUser/itemAdd.

  • CVE-2019-5318MedSep 7, 2021
    risk 0.42cvss 6.5epss 0.00

    A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6.x.x.x: all versions, 8.x.x.x: all versions prior to 8.8.0.0. Aruba has released patches for ArubaOS that address this security vulnerability.

  • CVE-2020-20343MedSep 1, 2021
    risk 0.42cvss 6.5epss 0.00

    WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.

  • CVE-2020-18123MedAug 30, 2021
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.

  • CVE-2021-39243MedAug 23, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100…

  • CVE-2020-28846MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.

  • CVE-2020-4992MedAug 17, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.

  • CVE-2020-25562MedAug 11, 2021
    risk 0.42cvss 6.5epss 0.01

    In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms like account resent.

  • CVE-2021-29400MedAug 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.

  • CVE-2021-24467MedAug 9, 2021
    risk 0.42cvss 6.5epss 0.01

    The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing…

  • CVE-2020-21358MedAug 6, 2021
    risk 0.42cvss 6.5epss 0.00

    A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.

  • CVE-2020-4675MedJul 16, 2021
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186324.

  • CVE-2020-27379MedJul 14, 2021
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF token is not being validated when the request is sent as a GET method. This results in an unauthorized change in the user's email ID, which can later be used…

  • CVE-2020-20468MedJun 21, 2021
    risk 0.42cvss 6.5epss 0.01

    White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the user password.

  • CVE-2020-35759MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.01

    bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).