CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 199 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20641 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2021 | Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted. | ||
| CVE-2021-20636 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2021 | Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted. | ||
| CVE-2020-13186 | Med | 0.42 | 6.5 | 0.00 | Feb 11, 2021 | An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link. | ||
| CVE-2020-35943 | Med | 0.42 | 6.5 | 0.01 | Feb 9, 2021 | A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.) | ||
| CVE-2021-22500 | Med | 0.42 | 6.5 | 0.00 | Feb 6, 2021 | Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing. | ||
| CVE-2020-9388 | Med | 0.42 | 6.5 | 0.01 | Feb 3, 2021 | CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard. | ||
| CVE-2021-3133 | Med | 0.42 | 6.5 | 0.01 | Jan 12, 2021 | The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages. | ||
| CVE-2020-35722 | Med | 0.42 | 6.5 | 0.01 | Jan 11, 2021 | CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||
| CVE-2020-36174 | Med | 0.42 | 6.5 | 0.01 | Jan 6, 2021 | The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. | ||
| CVE-2020-35347 | Med | 0.42 | 6.5 | 0.00 | Dec 26, 2020 | CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. | ||
| CVE-2020-4764 | Med | 0.42 | 6.5 | 0.00 | Dec 18, 2020 | IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 188898. | ||
| CVE-2020-4904 | Med | 0.42 | 6.5 | 0.00 | Dec 16, 2020 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | ||
| CVE-2020-4127 | Med | 0.42 | 6.5 | 0.00 | Nov 30, 2020 | HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions… | ||
| CVE-2020-17901 | Med | 0.42 | 6.5 | 0.00 | Nov 30, 2020 | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. | ||
| CVE-2020-25472 | Med | 0.42 | 6.5 | 0.01 | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users. | ||
| CVE-2020-5641 | Med | 0.42 | 6.5 | 0.01 | Nov 24, 2020 | Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may be changed without the user's intention or consent via unspecified vectors. | ||
| CVE-2020-22273 | Med | 0.42 | 6.5 | 0.00 | Nov 4, 2020 | Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings) | ||
| CVE-2020-5790 | Med | 0.42 | 6.5 | 0.02 | Oct 20, 2020 | Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | ||
| CVE-2020-4773 | Med | 0.42 | 6.5 | 0.01 | Oct 12, 2020 | A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a user to execute unwanted actions on the web application while they are currently authenticated. This applies to a single server… | ||
| CVE-2020-2295 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin. |
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.
- risk 0.42cvss 6.5epss 0.00
An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.
- risk 0.42cvss 6.5epss 0.01
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
- risk 0.42cvss 6.5epss 0.00
Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9.40, 9.50 and 9.51. The vulnerability could be exploited by attacker to trick the users into executing actions of the attacker's choosing.
- risk 0.42cvss 6.5epss 0.01
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.
- risk 0.42cvss 6.5epss 0.01
The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.
- risk 0.42cvss 6.5epss 0.01
CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- risk 0.42cvss 6.5epss 0.01
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
- risk 0.42cvss 6.5epss 0.00
CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.
- risk 0.42cvss 6.5epss 0.00
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 188898.
- risk 0.42cvss 6.5epss 0.00
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
- risk 0.42cvss 6.5epss 0.00
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions…
- risk 0.42cvss 6.5epss 0.00
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
- risk 0.42cvss 6.5epss 0.01
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may be changed without the user's intention or consent via unspecified vectors.
- risk 0.42cvss 6.5epss 0.00
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
- risk 0.42cvss 6.5epss 0.02
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
- risk 0.42cvss 6.5epss 0.01
A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a user to execute unwanted actions on the web application while they are currently authenticated. This applies to a single server…
- risk 0.42cvss 6.5epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin.