CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 208 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-16832 | Med | 0.42 | 6.5 | 0.01 | Sep 11, 2018 | CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header. | ||
| CVE-2018-16458 | Med | 0.42 | 6.5 | 0.00 | Sep 4, 2018 | An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article. | ||
| CVE-2018-16449 | Med | 0.42 | 6.5 | 0.01 | Sep 4, 2018 | OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html. | ||
| CVE-2018-16337 | Med | 0.42 | 6.5 | 0.00 | Sep 2, 2018 | An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save. | ||
| CVE-2018-16315 | Med | 0.42 | 6.5 | 0.00 | Sep 1, 2018 | In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add. | ||
| CVE-2018-15569 | Med | 0.42 | 6.5 | 0.00 | Aug 20, 2018 | my little forum 2.4.12 allows CSRF for deletion of users. | ||
| CVE-2018-13394 | Med | 0.42 | 6.5 | 0.01 | Aug 15, 2018 | The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery… | ||
| CVE-2018-13393 | Med | 0.42 | 6.5 | 0.01 | Aug 15, 2018 | The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request… | ||
| CVE-2018-15203 | Med | 0.42 | 6.5 | 0.00 | Aug 8, 2018 | An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages. | ||
| CVE-2018-1999027 | Hig | 0.42 | 7.5 | 0.01 | Aug 1, 2018 | An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins. | ||
| CVE-2018-10232 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2018 | Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecified vectors. | ||
| CVE-2018-12971 | Med | 0.42 | 6.5 | 0.00 | Jun 29, 2018 | EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users. | ||
| CVE-2018-1000507 | Med | 0.42 | 6.5 | 0.00 | Jun 26, 2018 | WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been… | ||
| CVE-2018-1000505 | Med | 0.42 | 6.5 | 0.01 | Jun 26, 2018 | Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been… | ||
| CVE-2018-12583 | Med | 0.42 | 6.5 | 0.00 | Jun 19, 2018 | An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php. | ||
| CVE-2018-11680 | Med | 0.42 | 6.5 | 0.00 | Jun 2, 2018 | An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate. | ||
| CVE-2018-11633 | Med | 0.42 | 6.5 | 0.01 | May 31, 2018 | An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings. The function… | ||
| CVE-2018-11632 | Med | 0.42 | 6.5 | 0.01 | May 31, 2018 | An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the… | ||
| CVE-2018-11096 | Med | 0.42 | 6.5 | 0.01 | May 21, 2018 | Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information remotely. | ||
| CVE-2018-11127 | Med | 0.42 | 6.5 | 0.01 | May 15, 2018 | e107 2.1.7 has CSRF resulting in arbitrary user deletion. |
- risk 0.42cvss 6.5epss 0.01
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article.
- risk 0.42cvss 6.5epss 0.01
OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.
- risk 0.42cvss 6.5epss 0.00
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
- risk 0.42cvss 6.5epss 0.00
my little forum 2.4.12 allows CSRF for deletion of users.
- risk 0.42cvss 6.5epss 0.01
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery…
- risk 0.42cvss 6.5epss 0.01
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request…
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.
- risk 0.42cvss 7.5epss 0.01
An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecified vectors.
- risk 0.42cvss 6.5epss 0.00
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
- risk 0.42cvss 6.5epss 0.00
WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been…
- risk 0.42cvss 6.5epss 0.01
Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been…
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings. The function…
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the…
- risk 0.42cvss 6.5epss 0.01
Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information remotely.
- risk 0.42cvss 6.5epss 0.01
e107 2.1.7 has CSRF resulting in arbitrary user deletion.