VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 202 of 482
  • CVE-2019-7654MedJan 29, 2020
    risk 0.42cvss 6.5epss 0.01

    Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users…

  • CVE-2014-2050MedJan 23, 2020
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.

  • CVE-2020-5502MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.00

    phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

  • CVE-2014-9382MedJan 13, 2020
    risk 0.42cvss 6.5epss 0.01

    Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation

  • CVE-2019-20178MedJan 9, 2020
    risk 0.42cvss 6.5epss 0.00

    Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.

  • CVE-2011-5250MedJan 8, 2020
    risk 0.42cvss 6.5epss 0.01

    Snare for Linux before 1.7.0 has CSRF in the web interface.

  • CVE-2014-5516MedJan 3, 2020
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a user email address via an unspecified GET request.

  • CVE-2014-3590MedJan 2, 2020
    risk 0.42cvss 6.5epss 0.01

    Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.

  • CVE-2019-12273MedDec 31, 2019
    risk 0.42cvss 6.5epss 0.00

    OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent…

  • CVE-2013-0196MedDec 30, 2019
    risk 0.42cvss 6.5epss 0.00

    A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web…

  • CVE-2019-20071MedDec 30, 2019
    risk 0.42cvss 6.5epss 0.01

    On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.

  • CVE-2017-18107MedDec 17, 2019
    risk 0.42cvss 6.5epss 0.00

    Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by…

  • CVE-2014-0026MedDec 11, 2019
    risk 0.42cvss 6.5epss 0.00

    katello-headpin is vulnerable to CSRF in REST API

  • CVE-2019-16002MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI…

  • CVE-2011-3609MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user…

  • CVE-2019-18651MedNov 14, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the…

  • CVE-2013-3516MedNov 13, 2019
    risk 0.42cvss 6.5epss 0.01

    NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.

  • CVE-2019-13497MedNov 4, 2019
    risk 0.42cvss 6.5epss 0.01

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

  • CVE-2019-8234MedOct 25, 2019
    risk 0.42cvss 6.5epss 0.02

    Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-9597MedOct 23, 2019
    risk 0.42cvss 6.5epss 0.01

    Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.