VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 203 of 482
  • CVE-2019-9596MedOct 23, 2019
    risk 0.42cvss 6.5epss 0.02

    Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.

  • CVE-2016-11015MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.01

    NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.

  • CVE-2019-17521MedOct 12, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,

  • CVE-2019-17432MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.

  • CVE-2019-17369MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.01

    OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.

  • CVE-2019-1915MedOct 2, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow…

  • CVE-2019-13376MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

  • CVE-2015-9447MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.

  • CVE-2015-9443MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.

  • CVE-2015-9442MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.

  • CVE-2015-9441MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.

  • CVE-2015-9440MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.

  • CVE-2015-9437MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.

  • CVE-2015-9434MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.

  • CVE-2015-9433MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php.

  • CVE-2015-9432MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.

  • CVE-2015-9431MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.

  • CVE-2015-9429MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.

  • CVE-2015-9428MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.

  • CVE-2015-9427MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter.