CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 209 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11003 | Med | 0.42 | 6.5 | 0.01 | May 12, 2018 | An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows remote attackers to delete administrator accounts via index.php?r=admin/admin/admindel. | ||
| CVE-2018-10758 | Med | 0.42 | 6.5 | 0.00 | May 5, 2018 | The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles. | ||
| CVE-2018-10248 | Med | 0.42 | 6.5 | 0.01 | Apr 20, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete. | ||
| CVE-2014-2675 | Med | 0.42 | 6.5 | 0.01 | Mar 19, 2018 | Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in… | ||
| CVE-2017-18033 | Med | 0.42 | 6.5 | 0.01 | Jan 18, 2018 | The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities. | ||
| CVE-2018-0785 | Med | 0.42 | 6.5 | 0.03 | Jan 10, 2018 | ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability". | ||
| CVE-2018-5301 | Med | 0.42 | 6.5 | 0.00 | Jan 8, 2018 | Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433. | ||
| CVE-2017-1000224 | Med | 0.42 | 6.5 | 0.01 | Nov 17, 2017 | CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin | ||
| CVE-2017-1000085 | Med | 0.42 | 6.5 | 0.01 | Oct 5, 2017 | Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Item/Configure) to connect to any web… | ||
| CVE-2016-2965 | Med | 0.42 | 6.5 | 0.01 | Aug 29, 2017 | IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846. | ||
| CVE-2016-0356 | Med | 0.42 | 6.5 | 0.01 | Aug 29, 2017 | IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895. | ||
| CVE-2016-0355 | Med | 0.42 | 6.5 | 0.01 | Aug 29, 2017 | IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894. | ||
| CVE-2017-8875 | Med | 0.42 | 6.5 | 0.01 | May 10, 2017 | CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL. | ||
| CVE-2017-8848 | Med | 0.42 | 6.5 | 0.00 | May 8, 2017 | Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. | ||
| CVE-2017-8100 | Med | 0.42 | 6.5 | 0.01 | Apr 24, 2017 | There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings. | ||
| CVE-2017-8098 | Med | 0.42 | 6.5 | 0.01 | Apr 24, 2017 | e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker. | ||
| CVE-2017-8082 | Med | 0.42 | 6.5 | 0.01 | Apr 24, 2017 | concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results… | ||
| CVE-2017-3877 | Med | 0.42 | 6.5 | 0.01 | Mar 17, 2017 | A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More Information:… | ||
| CVE-2016-6454 | Med | 0.42 | 6.5 | 0.01 | Nov 3, 2016 | A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to execute unwanted actions. More Information: CSCva54241. Known Affected Releases: 11.5(1).… | ||
| CVE-2009-3022 | Med | 0.42 | 6.5 | 0.01 | Aug 31, 2009 | Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors. |
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows remote attackers to delete administrator accounts via index.php?r=admin/admin/admindel.
- risk 0.42cvss 6.5epss 0.00
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in…
- risk 0.42cvss 6.5epss 0.01
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
- risk 0.42cvss 6.5epss 0.03
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
- risk 0.42cvss 6.5epss 0.00
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.
- risk 0.42cvss 6.5epss 0.01
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
- risk 0.42cvss 6.5epss 0.01
Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Item/Configure) to connect to any web…
- risk 0.42cvss 6.5epss 0.01
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846.
- risk 0.42cvss 6.5epss 0.01
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.
- risk 0.42cvss 6.5epss 0.01
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894.
- risk 0.42cvss 6.5epss 0.01
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
- risk 0.42cvss 6.5epss 0.00
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
- risk 0.42cvss 6.5epss 0.01
There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.
- risk 0.42cvss 6.5epss 0.01
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.
- risk 0.42cvss 6.5epss 0.01
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results…
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More Information:…
- risk 0.42cvss 6.5epss 0.01
A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to execute unwanted actions. More Information: CSCva54241. Known Affected Releases: 11.5(1).…
- risk 0.42cvss 6.5epss 0.01
Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.