CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 202 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-7654 | Med | 0.42 | 6.5 | 0.01 | Jan 29, 2020 | Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users… | ||
| CVE-2014-2050 | Med | 0.42 | 6.5 | 0.01 | Jan 23, 2020 | Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header. | ||
| CVE-2020-5502 | Med | 0.42 | 6.5 | 0.00 | Jan 15, 2020 | phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships. | ||
| CVE-2014-9382 | Med | 0.42 | 6.5 | 0.01 | Jan 13, 2020 | Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation | ||
| CVE-2019-20178 | Med | 0.42 | 6.5 | 0.00 | Jan 9, 2020 | Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user. | ||
| CVE-2011-5250 | Med | 0.42 | 6.5 | 0.01 | Jan 8, 2020 | Snare for Linux before 1.7.0 has CSRF in the web interface. | ||
| CVE-2014-5516 | Med | 0.42 | 6.5 | 0.01 | Jan 3, 2020 | Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a user email address via an unspecified GET request. | ||
| CVE-2014-3590 | Med | 0.42 | 6.5 | 0.01 | Jan 2, 2020 | Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content. | ||
| CVE-2019-12273 | Med | 0.42 | 6.5 | 0.00 | Dec 31, 2019 | OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent… | ||
| CVE-2013-0196 | Med | 0.42 | 6.5 | 0.00 | Dec 30, 2019 | A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web… | ||
| CVE-2019-20071 | Med | 0.42 | 6.5 | 0.01 | Dec 30, 2019 | On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs. | ||
| CVE-2017-18107 | Med | 0.42 | 6.5 | 0.00 | Dec 17, 2019 | Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by… | ||
| CVE-2014-0026 | Med | 0.42 | 6.5 | 0.00 | Dec 11, 2019 | katello-headpin is vulnerable to CSRF in REST API | ||
| CVE-2019-16002 | Med | 0.42 | 6.5 | 0.01 | Nov 26, 2019 | A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI… | ||
| CVE-2011-3609 | Med | 0.42 | 6.5 | 0.01 | Nov 26, 2019 | A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user… | ||
| CVE-2019-18651 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2019 | A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the… | ||
| CVE-2013-3516 | Med | 0.42 | 6.5 | 0.01 | Nov 13, 2019 | NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens. | ||
| CVE-2019-13497 | Med | 0.42 | 6.5 | 0.01 | Nov 4, 2019 | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests. | ||
| CVE-2019-8234 | Med | 0.42 | 6.5 | 0.02 | Oct 25, 2019 | Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure. | ||
| CVE-2019-9597 | Med | 0.42 | 6.5 | 0.01 | Oct 23, 2019 | Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint. |
- risk 0.42cvss 6.5epss 0.01
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users…
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
- risk 0.42cvss 6.5epss 0.00
phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
- risk 0.42cvss 6.5epss 0.01
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
- risk 0.42cvss 6.5epss 0.00
Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
- risk 0.42cvss 6.5epss 0.01
Snare for Linux before 1.7.0 has CSRF in the web interface.
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a user email address via an unspecified GET request.
- risk 0.42cvss 6.5epss 0.01
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.
- risk 0.42cvss 6.5epss 0.00
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent…
- risk 0.42cvss 6.5epss 0.00
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web…
- risk 0.42cvss 6.5epss 0.01
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
- risk 0.42cvss 6.5epss 0.00
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by…
- risk 0.42cvss 6.5epss 0.00
katello-headpin is vulnerable to CSRF in REST API
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI…
- risk 0.42cvss 6.5epss 0.01
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user…
- risk 0.42cvss 6.5epss 0.01
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the…
- risk 0.42cvss 6.5epss 0.01
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
- risk 0.42cvss 6.5epss 0.01
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
- risk 0.42cvss 6.5epss 0.02
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
- risk 0.42cvss 6.5epss 0.01
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.