CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 207 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9049 | Med | 0.42 | 6.5 | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI. | ||
| CVE-2019-9048 | Med | 0.42 | 6.5 | 0.01 | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI. | ||
| CVE-2019-7570 | Med | 0.42 | 6.5 | 0.01 | Feb 7, 2019 | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. | ||
| CVE-2019-1003022 | Med | 0.42 | 6.5 | 0.01 | Feb 6, 2019 | A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master. | ||
| CVE-2018-8892 | Med | 0.42 | 6.5 | 0.00 | Dec 20, 2018 | A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator. | ||
| CVE-2018-1661 | Med | 0.42 | 6.5 | 0.01 | Dec 20, 2018 | IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887. | ||
| CVE-2018-18246 | Med | 0.42 | 6.5 | 0.00 | Dec 17, 2018 | Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module. | ||
| CVE-2018-1927 | Med | 0.42 | 6.5 | 0.01 | Nov 30, 2018 | IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153118. | ||
| CVE-2018-19621 | Med | 0.42 | 6.5 | 0.00 | Nov 28, 2018 | server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team. | ||
| CVE-2018-19544 | Med | 0.42 | 6.5 | 0.00 | Nov 26, 2018 | JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. | ||
| CVE-2018-19376 | Med | 0.42 | 6.5 | 0.01 | Nov 20, 2018 | An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI. | ||
| CVE-2018-19319 | Med | 0.42 | 6.5 | 0.00 | Nov 16, 2018 | SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges. | ||
| CVE-2018-19291 | Med | 0.42 | 6.5 | 0.01 | Nov 15, 2018 | An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI. | ||
| CVE-2018-15438 | Med | 0.42 | 6.5 | 0.01 | Oct 17, 2018 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to… | ||
| CVE-2018-2474 | Med | 0.42 | 6.5 | 0.01 | Oct 9, 2018 | SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection. | ||
| CVE-2018-15401 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2018 | A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability… | ||
| CVE-2017-15608 | Med | 0.42 | 6.5 | 0.00 | Sep 26, 2018 | Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings. | ||
| CVE-2018-13398 | Med | 0.42 | 6.5 | 0.01 | Sep 18, 2018 | The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability. | ||
| CVE-2018-17070 | Med | 0.42 | 6.5 | 0.01 | Sep 15, 2018 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay. | ||
| CVE-2018-17069 | Med | 0.42 | 6.5 | 0.01 | Sep 15, 2018 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay. |
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
- risk 0.42cvss 6.5epss 0.01
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
- risk 0.42cvss 6.5epss 0.01
A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.
- risk 0.42cvss 6.5epss 0.00
A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.
- risk 0.42cvss 6.5epss 0.01
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.
- risk 0.42cvss 6.5epss 0.00
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
- risk 0.42cvss 6.5epss 0.01
IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153118.
- risk 0.42cvss 6.5epss 0.00
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
- risk 0.42cvss 6.5epss 0.00
JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI.
- risk 0.42cvss 6.5epss 0.00
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to…
- risk 0.42cvss 6.5epss 0.01
SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability…
- risk 0.42cvss 6.5epss 0.00
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
- risk 0.42cvss 6.5epss 0.01
The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.