VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 199 of 482
  • CVE-2021-20641MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2021-20636MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.

  • CVE-2020-13186MedFeb 11, 2021
    risk 0.42cvss 6.5epss 0.00

    An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.

  • CVE-2020-35943MedFeb 9, 2021
    risk 0.42cvss 6.5epss 0.01

    A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)

  • CVE-2021-22500MedFeb 6, 2021
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.

  • CVE-2020-9388MedFeb 3, 2021
    risk 0.42cvss 6.5epss 0.01

    CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

  • CVE-2021-3133MedJan 12, 2021
    risk 0.42cvss 6.5epss 0.01

    The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.

  • CVE-2020-35722MedJan 11, 2021
    risk 0.42cvss 6.5epss 0.01

    CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2020-36174MedJan 6, 2021
    risk 0.42cvss 6.5epss 0.01

    The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.

  • CVE-2020-35347MedDec 26, 2020
    risk 0.42cvss 6.5epss 0.00

    CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.

  • CVE-2020-4764MedDec 18, 2020
    risk 0.42cvss 6.5epss 0.00

    IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 188898.

  • CVE-2020-4904MedDec 16, 2020
    risk 0.42cvss 6.5epss 0.00

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2020-4127MedNov 30, 2020
    risk 0.42cvss 6.5epss 0.00

    HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions…

  • CVE-2020-17901MedNov 30, 2020
    risk 0.42cvss 6.5epss 0.00

    Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.

  • CVE-2020-25472MedNov 24, 2020
    risk 0.42cvss 6.5epss 0.01

    SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.

  • CVE-2020-5641MedNov 24, 2020
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may be changed without the user's intention or consent via unspecified vectors.

  • CVE-2020-22273MedNov 4, 2020
    risk 0.42cvss 6.5epss 0.00

    Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)

  • CVE-2020-5790MedOct 20, 2020
    risk 0.42cvss 6.5epss 0.02

    Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

  • CVE-2020-4773MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a user to execute unwanted actions on the web application while they are currently authenticated. This applies to a single server…

  • CVE-2020-2295MedOct 8, 2020
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin.