VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 207 of 482
  • CVE-2019-9049MedFeb 23, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.

  • CVE-2019-9048MedFeb 23, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.

  • CVE-2019-7570MedFeb 7, 2019
    risk 0.42cvss 6.5epss 0.01

    A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.

  • CVE-2019-1003022MedFeb 6, 2019
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.

  • CVE-2018-8892MedDec 20, 2018
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.

  • CVE-2018-1661MedDec 20, 2018
    risk 0.42cvss 6.5epss 0.01

    IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.

  • CVE-2018-18246MedDec 17, 2018
    risk 0.42cvss 6.5epss 0.00

    Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.

  • CVE-2018-1927MedNov 30, 2018
    risk 0.42cvss 6.5epss 0.01

    IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153118.

  • CVE-2018-19621MedNov 28, 2018
    risk 0.42cvss 6.5epss 0.00

    server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

  • CVE-2018-19544MedNov 26, 2018
    risk 0.42cvss 6.5epss 0.00

    JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.

  • CVE-2018-19376MedNov 20, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI.

  • CVE-2018-19319MedNov 16, 2018
    risk 0.42cvss 6.5epss 0.00

    SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.

  • CVE-2018-19291MedNov 15, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.

  • CVE-2018-15438MedOct 17, 2018
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to…

  • CVE-2018-2474MedOct 9, 2018
    risk 0.42cvss 6.5epss 0.01

    SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.

  • CVE-2018-15401MedOct 5, 2018
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability…

  • CVE-2017-15608MedSep 26, 2018
    risk 0.42cvss 6.5epss 0.00

    Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.

  • CVE-2018-13398MedSep 18, 2018
    risk 0.42cvss 6.5epss 0.01

    The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.

  • CVE-2018-17070MedSep 15, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay.

  • CVE-2018-17069MedSep 15, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.