VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 200 of 482
  • CVE-2020-25986MedOct 6, 2020
    risk 0.42cvss 6.5epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.

  • CVE-2020-24570MedSep 30, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.

  • CVE-2020-25142MedSep 25, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable if any links and forms lack an unpredictable CSRF token. Without such a token, attackers can forge malicious requests, such as for adding Device Settings via the /addsrv URI.

  • CVE-2020-12841MedSep 24, 2020
    risk 0.42cvss 6.5epss 0.00

    ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php

  • CVE-2020-12840MedSep 24, 2020
    risk 0.42cvss 6.5epss 0.00

    ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php

  • CVE-2020-12281MedSep 24, 2020
    risk 0.42cvss 6.5epss 0.00

    iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php.

  • CVE-2020-12280MedSep 24, 2020
    risk 0.42cvss 6.5epss 0.00

    iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to open/close a specified garage door/gate via /isg/opendoor.php.

  • CVE-2020-3124MedSep 23, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2020-24739MedSep 10, 2020
    risk 0.42cvss 6.5epss 0.00

    A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.

  • CVE-2020-7029MedAug 11, 2020
    risk 0.42cvss 6.4epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions…

  • CVE-2020-5767MedJul 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.

  • CVE-2020-10986MedJul 13, 2020
    risk 0.42cvss 6.5epss 0.01

    A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.

  • CVE-2020-15043MedJun 29, 2020
    risk 0.42cvss 6.5epss 0.00

    iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.

  • CVE-2020-13157MedJun 23, 2020
    risk 0.42cvss 6.5epss 0.01

    modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.

  • CVE-2020-13156MedJun 23, 2020
    risk 0.42cvss 6.5epss 0.01

    modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

  • CVE-2020-13426MedJun 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.

  • CVE-2020-8167MedJun 19, 2020
    risk 0.42cvss 6.5epss 0.01

    A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

  • CVE-2020-13868MedJun 5, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.

  • CVE-2020-11682MedJun 4, 2020
    risk 0.42cvss 6.5epss 0.01

    Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all…

  • CVE-2020-13416MedMay 22, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.