CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 201 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1103 | Med | 0.42 | 6.5 | 0.02 | May 21, 2020 | An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultaneously logged in to Microsoft SharePoint… | ||
| CVE-2020-13231 | Med | 0.42 | 6.5 | 0.01 | May 20, 2020 | In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change. | ||
| CVE-2020-4286 | Med | 0.42 | 6.5 | 0.00 | May 19, 2020 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176268. | ||
| CVE-2020-5517 | Med | 0.42 | 6.5 | 0.01 | May 5, 2020 | CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analysis. | ||
| CVE-2020-3261 | Med | 0.42 | 6.5 | 0.01 | Apr 15, 2020 | A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the… | ||
| CVE-2019-13199 | Med | 0.42 | 6.5 | 0.01 | Mar 13, 2020 | Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device. | ||
| CVE-2019-13170 | Med | 0.42 | 6.5 | 0.00 | Mar 13, 2020 | Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device. | ||
| CVE-2020-10501 | Med | 0.42 | 6.5 | 0.01 | Mar 12, 2020 | CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request. | ||
| CVE-2020-10498 | Med | 0.42 | 6.5 | 0.01 | Mar 12, 2020 | CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request. | ||
| CVE-2020-10497 | Med | 0.42 | 6.5 | 0.01 | Mar 12, 2020 | CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request. | ||
| CVE-2019-19987 | Med | 0.42 | 6.5 | 0.01 | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An attacker can exploit the vulnerability to abuse functionalities such as change password, add user, add privilege, and so on. | ||
| CVE-2020-9271 | Med | 0.42 | 6.5 | 0.00 | Feb 18, 2020 | ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php. | ||
| CVE-2020-9267 | Med | 0.42 | 6.5 | 0.01 | Feb 18, 2020 | SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php. | ||
| CVE-2020-9266 | Med | 0.42 | 6.5 | 0.01 | Feb 18, 2020 | SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php. | ||
| CVE-2019-19669 | Med | 0.42 | 6.5 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could allow an attacker to delete, create, and update the upload forms via RAPR/TriggerServerFunction.html. | ||
| CVE-2019-19662 | Med | 0.42 | 6.5 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can Create and Delete accounts via RAPR/TriggerServerFunction.html. | ||
| CVE-2019-19665 | Med | 0.42 | 6.5 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.html. | ||
| CVE-2019-19663 | Med | 0.42 | 6.5 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders after exploiting it at RAPR/FolderSetsSet.html. | ||
| CVE-2019-19660 | Med | 0.42 | 6.5 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html. | ||
| CVE-2019-20401 | Med | 0.42 | 6.5 | 0.01 | Feb 6, 2020 | Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities. |
- risk 0.42cvss 6.5epss 0.02
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultaneously logged in to Microsoft SharePoint…
- risk 0.42cvss 6.5epss 0.01
In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
- risk 0.42cvss 6.5epss 0.00
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 176268.
- risk 0.42cvss 6.5epss 0.01
CSRF in the /login URI in BlueOnyx 5209R allows an attacker to access the dashboard and perform scraping or other analysis.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the…
- risk 0.42cvss 6.5epss 0.01
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
- risk 0.42cvss 6.5epss 0.00
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
- risk 0.42cvss 6.5epss 0.01
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.
- risk 0.42cvss 6.5epss 0.01
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
- risk 0.42cvss 6.5epss 0.01
CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An attacker can exploit the vulnerability to abuse functionalities such as change password, add user, add privilege, and so on.
- risk 0.42cvss 6.5epss 0.00
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
- risk 0.42cvss 6.5epss 0.01
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
- risk 0.42cvss 6.5epss 0.01
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
- risk 0.42cvss 6.5epss 0.00
A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could allow an attacker to delete, create, and update the upload forms via RAPR/TriggerServerFunction.html.
- risk 0.42cvss 6.5epss 0.00
A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can Create and Delete accounts via RAPR/TriggerServerFunction.html.
- risk 0.42cvss 6.5epss 0.00
A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.html.
- risk 0.42cvss 6.5epss 0.00
A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders after exploiting it at RAPR/FolderSetsSet.html.
- risk 0.42cvss 6.5epss 0.00
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.
- risk 0.42cvss 6.5epss 0.01
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.