VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 208 of 482
  • CVE-2018-16832MedSep 11, 2018
    risk 0.42cvss 6.5epss 0.01

    CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.

  • CVE-2018-16458MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article.

  • CVE-2018-16449MedSep 4, 2018
    risk 0.42cvss 6.5epss 0.01

    OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.

  • CVE-2018-16337MedSep 2, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.

  • CVE-2018-16315MedSep 1, 2018
    risk 0.42cvss 6.5epss 0.00

    In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.

  • CVE-2018-15569MedAug 20, 2018
    risk 0.42cvss 6.5epss 0.00

    my little forum 2.4.12 allows CSRF for deletion of users.

  • CVE-2018-13394MedAug 15, 2018
    risk 0.42cvss 6.5epss 0.01

    The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery…

  • CVE-2018-13393MedAug 15, 2018
    risk 0.42cvss 6.5epss 0.01

    The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request…

  • CVE-2018-15203MedAug 8, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.

  • CVE-2018-1999027HigAug 1, 2018
    risk 0.42cvss 7.5epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

  • CVE-2018-10232MedJul 11, 2018
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecified vectors.

  • CVE-2018-12971MedJun 29, 2018
    risk 0.42cvss 6.5epss 0.00

    EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.

  • CVE-2018-1000507MedJun 26, 2018
    risk 0.42cvss 6.5epss 0.00

    WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been…

  • CVE-2018-1000505MedJun 26, 2018
    risk 0.42cvss 6.5epss 0.01

    Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been…

  • CVE-2018-12583MedJun 19, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.

  • CVE-2018-11680MedJun 2, 2018
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.

  • CVE-2018-11633MedMay 31, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings. The function…

  • CVE-2018-11632MedMay 31, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the…

  • CVE-2018-11096MedMay 21, 2018
    risk 0.42cvss 6.5epss 0.01

    Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information remotely.

  • CVE-2018-11127MedMay 15, 2018
    risk 0.42cvss 6.5epss 0.01

    e107 2.1.7 has CSRF resulting in arbitrary user deletion.