VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 205 of 482
  • CVE-2019-15128MedSep 6, 2019
    risk 0.42cvss 6.5epss 0.01

    iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.

  • CVE-2019-10057MedAug 28, 2019
    risk 0.42cvss 6.5epss 0.00

    Various Lexmark products have CSRF.

  • CVE-2019-15648MedAug 27, 2019
    risk 0.42cvss 6.5epss 0.01

    The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.

  • CVE-2019-11587MedAug 23, 2019
    risk 0.42cvss 6.5epss 0.01

    Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).

  • CVE-2019-4167MedAug 20, 2019
    risk 0.42cvss 6.5epss 0.00

    IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158700.

  • CVE-2015-9332MedAug 20, 2019
    risk 0.42cvss 6.5epss 0.01

    The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.

  • CVE-2016-10883MedAug 14, 2019
    risk 0.42cvss 6.5epss 0.01

    The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.

  • CVE-2019-14679MedAug 8, 2019
    risk 0.42cvss 6.5epss 0.01

    core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.

  • CVE-2016-10861MedAug 7, 2019
    risk 0.42cvss 6.5epss 0.01

    Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.

  • CVE-2018-20872MedJul 31, 2019
    risk 0.42cvss 6.5epss 0.01

    DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.

  • CVE-2019-14327MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.

  • CVE-2019-7953MedJul 18, 2019
    risk 0.42cvss 6.5epss 0.03

    Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.

  • CVE-2019-10353HigJul 17, 2019
    risk 0.42cvss 7.5epss 0.01

    CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.

  • CVE-2019-12923MedJul 8, 2019
    risk 0.42cvss 6.5epss 0.01

    In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a…

  • CVE-2019-5814MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-0996MedJun 12, 2019
    risk 0.42cvss 6.5epss 0.02

    A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application…

  • CVE-2019-11517MedJun 10, 2019
    risk 0.42cvss 6.5epss 0.00

    WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.

  • CVE-2018-19613MedMay 24, 2019
    risk 0.42cvss 6.5epss 0.01

    Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.

  • CVE-2019-12253MedMay 21, 2019
    risk 0.42cvss 6.5epss 0.01

    my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.

  • CVE-2018-14711MedMay 13, 2019
    risk 0.42cvss 6.5epss 0.01

    Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.