CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 205 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15128 | Med | 0.42 | 6.5 | 0.01 | Sep 6, 2019 | iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user. | ||
| CVE-2019-10057 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2019 | Various Lexmark products have CSRF. | ||
| CVE-2019-15648 | Med | 0.42 | 6.5 | 0.01 | Aug 27, 2019 | The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. | ||
| CVE-2019-11587 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2019 | Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF). | ||
| CVE-2019-4167 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2019 | IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158700. | ||
| CVE-2015-9332 | Med | 0.42 | 6.5 | 0.01 | Aug 20, 2019 | The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI. | ||
| CVE-2016-10883 | Med | 0.42 | 6.5 | 0.01 | Aug 14, 2019 | The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. | ||
| CVE-2019-14679 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2019 | core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF. | ||
| CVE-2016-10861 | Med | 0.42 | 6.5 | 0.01 | Aug 7, 2019 | Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password. | ||
| CVE-2018-20872 | Med | 0.42 | 6.5 | 0.01 | Jul 31, 2019 | DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649. | ||
| CVE-2019-14327 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2019 | A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings. | ||
| CVE-2019-7953 | Med | 0.42 | 6.5 | 0.03 | Jul 18, 2019 | Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user. | ||
| CVE-2019-10353 | Hig | 0.42 | 7.5 | 0.01 | Jul 17, 2019 | CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection. | ||
| CVE-2019-12923 | Med | 0.42 | 6.5 | 0.01 | Jul 8, 2019 | In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a… | ||
| CVE-2019-5814 | Med | 0.42 | 6.5 | 0.01 | Jun 27, 2019 | Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2019-0996 | Med | 0.42 | 6.5 | 0.02 | Jun 12, 2019 | A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application… | ||
| CVE-2019-11517 | Med | 0.42 | 6.5 | 0.00 | Jun 10, 2019 | WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner. | ||
| CVE-2018-19613 | Med | 0.42 | 6.5 | 0.01 | May 24, 2019 | Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF. | ||
| CVE-2019-12253 | Med | 0.42 | 6.5 | 0.01 | May 21, 2019 | my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting. | ||
| CVE-2018-14711 | Med | 0.42 | 6.5 | 0.01 | May 13, 2019 | Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs. |
- risk 0.42cvss 6.5epss 0.01
iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.
- risk 0.42cvss 6.5epss 0.00
Various Lexmark products have CSRF.
- risk 0.42cvss 6.5epss 0.01
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
- risk 0.42cvss 6.5epss 0.01
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).
- risk 0.42cvss 6.5epss 0.00
IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158700.
- risk 0.42cvss 6.5epss 0.01
The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.
- risk 0.42cvss 6.5epss 0.01
The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
- risk 0.42cvss 6.5epss 0.01
core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
- risk 0.42cvss 6.5epss 0.01
Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.
- risk 0.42cvss 6.5epss 0.01
DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.
- risk 0.42cvss 6.5epss 0.01
A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.
- risk 0.42cvss 6.5epss 0.03
Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
- risk 0.42cvss 7.5epss 0.01
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
- risk 0.42cvss 6.5epss 0.01
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a…
- risk 0.42cvss 6.5epss 0.01
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- risk 0.42cvss 6.5epss 0.02
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application…
- risk 0.42cvss 6.5epss 0.00
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.
- risk 0.42cvss 6.5epss 0.01
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
- risk 0.42cvss 6.5epss 0.01
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
- risk 0.42cvss 6.5epss 0.01
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.