CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 203 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9596 | Med | 0.42 | 6.5 | 0.02 | Oct 23, 2019 | Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint. | ||
| CVE-2016-11015 | Med | 0.42 | 6.5 | 0.01 | Oct 16, 2019 | NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter. | ||
| CVE-2019-17521 | Med | 0.42 | 6.5 | 0.00 | Oct 12, 2019 | An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI, | ||
| CVE-2019-17432 | Med | 0.42 | 6.5 | 0.01 | Oct 10, 2019 | An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter. | ||
| CVE-2019-17369 | Med | 0.42 | 6.5 | 0.01 | Oct 9, 2019 | OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin. | ||
| CVE-2019-1915 | Med | 0.42 | 6.5 | 0.01 | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow… | ||
| CVE-2019-13376 | Med | 0.42 | 6.5 | 0.01 | Sep 27, 2019 | phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS | ||
| CVE-2015-9447 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters. | ||
| CVE-2015-9443 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP. | ||
| CVE-2015-9442 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin. | ||
| CVE-2015-9441 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php. | ||
| CVE-2015-9440 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new. | ||
| CVE-2015-9437 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter. | ||
| CVE-2015-9434 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter. | ||
| CVE-2015-9433 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php. | ||
| CVE-2015-9432 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter. | ||
| CVE-2015-9431 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter. | ||
| CVE-2015-9429 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter. | ||
| CVE-2015-9428 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters. | ||
| CVE-2015-9427 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter. |
- risk 0.42cvss 6.5epss 0.02
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
- risk 0.42cvss 6.5epss 0.01
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.
- risk 0.42cvss 6.5epss 0.01
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow…
- risk 0.42cvss 6.5epss 0.01
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
- risk 0.42cvss 6.5epss 0.01
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
- risk 0.42cvss 6.5epss 0.01
The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.
- risk 0.42cvss 6.5epss 0.01
The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.
- risk 0.42cvss 6.5epss 0.01
The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.
- risk 0.42cvss 6.5epss 0.01
The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.
- risk 0.42cvss 6.5epss 0.01
The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.
- risk 0.42cvss 6.5epss 0.01
The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.
- risk 0.42cvss 6.5epss 0.01
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php.
- risk 0.42cvss 6.5epss 0.01
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
- risk 0.42cvss 6.5epss 0.01
The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.
- risk 0.42cvss 6.5epss 0.01
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.
- risk 0.42cvss 6.5epss 0.01
The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.
- risk 0.42cvss 6.5epss 0.01
The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter.