VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,651)

page 24 of 483
  • CVE-2024-42631HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.

  • CVE-2024-42630HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.

  • CVE-2024-42629HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

  • CVE-2024-42628HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.

  • CVE-2024-40488HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the…

  • CVE-2024-7492HigAug 8, 2024
    risk 0.57cvss 8.8epss 0.00

    The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated…

  • CVE-2024-6720HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.00

    The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-3238HigAug 2, 2024
    risk 0.57cvss 8.8epss 0.00

    The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it…

  • CVE-2024-6040HigAug 1, 2024
    risk 0.57cvss 8.8epss 0.00

    In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /install_binding, /reinstall_binding, /unInstall_binding,…

  • CVE-2024-40883HigAug 1, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login…

  • CVE-2024-41602HigJul 19, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL

  • CVE-2024-40119HigJul 17, 2024
    risk 0.57cvss 8.8epss 0.01

    Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without the user's consent, leading to a…

  • CVE-2024-6075HigJul 15, 2024
    risk 0.57cvss 8.8epss 0.00

    The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-5076HigJul 13, 2024
    risk 0.57cvss 8.8epss 0.00

    The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-5034HigJul 13, 2024
    risk 0.57cvss 8.8epss 0.00

    The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-6024HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.00

    The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack

  • CVE-2024-6023HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.00

    The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack

  • CVE-2024-6022HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.00

    The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2024-1845HigJul 11, 2024
    risk 0.57cvss 8.8epss 0.00

    The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-40332HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord