VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 204 of 482
  • CVE-2015-9424MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.

  • CVE-2015-9422MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.

  • CVE-2015-9421MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.

  • CVE-2015-9417MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.

  • CVE-2015-9413MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.

  • CVE-2015-9409MedSep 25, 2019
    risk 0.42cvss 6.5epss 0.01

    The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.

  • CVE-2019-4515MedSep 24, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 165137.

  • CVE-2019-16721MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.01

    NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.

  • CVE-2019-16719MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.01

    WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.

  • CVE-2019-16678MedSep 21, 2019
    risk 0.42cvss 6.5epss 0.01

    admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.

  • CVE-2019-16677MedSep 21, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.

  • CVE-2018-17789MedSep 20, 2019
    risk 0.42cvss 6.5epss 0.01

    Prospecta Master Data Online (MDO) allows CSRF.

  • CVE-2015-9408MedSep 20, 2019
    risk 0.42cvss 6.5epss 0.01

    The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.

  • CVE-2016-10997MedSep 20, 2019
    risk 0.42cvss 6.5epss 0.01

    The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.

  • CVE-2015-9388MedSep 20, 2019
    risk 0.42cvss 6.5epss 0.01

    The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.

  • CVE-2015-9387MedSep 20, 2019
    risk 0.42cvss 6.5epss 0.01

    The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.

  • CVE-2016-10962MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

  • CVE-2016-10938MedSep 13, 2019
    risk 0.42cvss 6.5epss 0.01

    The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.

  • CVE-2019-14998MedSep 11, 2019
    risk 0.42cvss 6.5epss 0.01

    The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.

  • CVE-2019-10253MedSep 9, 2019
    risk 0.42cvss 6.5epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists…