VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 209 of 482
  • CVE-2018-11003MedMay 12, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows remote attackers to delete administrator accounts via index.php?r=admin/admin/admindel.

  • CVE-2018-10758MedMay 5, 2018
    risk 0.42cvss 6.5epss 0.00

    The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.

  • CVE-2018-10248MedApr 20, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.

  • CVE-2014-2675MedMar 19, 2018
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in…

  • CVE-2017-18033MedJan 18, 2018
    risk 0.42cvss 6.5epss 0.01

    The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.

  • CVE-2018-0785MedJan 10, 2018
    risk 0.42cvss 6.5epss 0.03

    ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".

  • CVE-2018-5301MedJan 8, 2018
    risk 0.42cvss 6.5epss 0.00

    Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.

  • CVE-2017-1000224MedNov 17, 2017
    risk 0.42cvss 6.5epss 0.01

    CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin

  • CVE-2017-1000085MedOct 5, 2017
    risk 0.42cvss 6.5epss 0.01

    Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Item/Configure) to connect to any web…

  • CVE-2016-2965MedAug 29, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846.

  • CVE-2016-0356MedAug 29, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.

  • CVE-2016-0355MedAug 29, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894.

  • CVE-2017-8875MedMay 10, 2017
    risk 0.42cvss 6.5epss 0.01

    CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

  • CVE-2017-8848MedMay 8, 2017
    risk 0.42cvss 6.5epss 0.00

    Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.

  • CVE-2017-8100MedApr 24, 2017
    risk 0.42cvss 6.5epss 0.01

    There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.

  • CVE-2017-8098MedApr 24, 2017
    risk 0.42cvss 6.5epss 0.01

    e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.

  • CVE-2017-8082MedApr 24, 2017
    risk 0.42cvss 6.5epss 0.01

    concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results…

  • CVE-2017-3877MedMar 17, 2017
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More Information:…

  • CVE-2016-6454MedNov 3, 2016
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to execute unwanted actions. More Information: CSCva54241. Known Affected Releases: 11.5(1).…

  • CVE-2009-3022MedAug 31, 2009
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.