VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 266 of 482
  • CVE-2021-25326MedApr 9, 2021
    risk 0.35cvss 5.4epss 0.01

    Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user visits a URL, the SSID password and web UI password may be disclosed.

  • CVE-2021-22512MedApr 8, 2021
    risk 0.35cvss 6.5epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow form validation without permission checks.

  • CVE-2021-24166MedApr 5, 2021
    risk 0.35cvss 5.4epss 0.00

    The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.

  • CVE-2020-26033MedDec 28, 2020
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.

  • CVE-2019-14481MedDec 16, 2020
    risk 0.35cvss 5.4epss 0.00

    AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.

  • CVE-2020-5783MedSep 23, 2020
    risk 0.35cvss 5.4epss 0.00

    In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.

  • CVE-2020-12480MedAug 17, 2020
    risk 0.35cvss 6.5epss 0.01

    In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.

  • CVE-2016-11085MedAug 16, 2020
    risk 0.35cvss 6.5epss 0.01

    php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.

  • CVE-2020-15516MedJul 7, 2020
    risk 0.35cvss 5.4epss 0.00

    The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.

  • CVE-2020-2192MedJun 3, 2020
    risk 0.35cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels.

  • CVE-2019-19667MedFeb 10, 2020
    risk 0.35cvss 5.4epss 0.00

    A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an attacker to whitelist or block any IP address via RAPR/BlockedClients.html.

  • CVE-2019-19981MedDec 26, 2019
    risk 0.35cvss 5.4epss 0.01

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.

  • CVE-2015-9425MedSep 26, 2019
    risk 0.35cvss 5.4epss 0.01

    The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.

  • CVE-2017-18485MedAug 8, 2019
    risk 0.35cvss 5.4epss 0.01

    Cognitoys Dino devices allow profiles_add.html CSRF.

  • CVE-2019-7947MedAug 2, 2019
    risk 0.35cvss 6.5epss 0.00

    A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

  • CVE-2019-7874MedAug 2, 2019
    risk 0.35cvss 6.5epss 0.00

    A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of user roles.

  • CVE-2019-7851MedAug 2, 2019
    risk 0.35cvss 6.5epss 0.00

    A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.

  • CVE-2019-10324MedMay 31, 2019
    risk 0.35cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform…

  • CVE-2019-5431MedMay 6, 2019
    risk 0.35cvss 5.4epss 0.00

    This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login…

  • CVE-2019-10307MedApr 30, 2019
    risk 0.35cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers to change the per-job default graph configuration for all users.