VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,651)

page 28 of 483
  • CVE-2024-28684HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_main.php

  • CVE-2024-28675HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php

  • CVE-2024-28665HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php

  • CVE-2024-28432HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.

  • CVE-2024-28431HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.

  • CVE-2024-0203HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.00

    The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_settings' function. This makes it possible for unauthenticated attackers to modify the default role of…

  • CVE-2024-27689HigMar 1, 2024
    risk 0.57cvss 8.8epss 0.00

    Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.

  • CVE-2024-22939HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

  • CVE-2024-23910HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B…

  • CVE-2023-52047HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

  • CVE-2024-1889HigFeb 26, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.

  • CVE-2024-26352HigFeb 22, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php

  • CVE-2024-26350HigFeb 22, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.php

  • CVE-2024-23094HigFeb 22, 2024
    risk 0.57cvss 8.8epss 0.00

    Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/edit_addon_post.php

  • CVE-2023-52431HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.00

    The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if signed cookies are disabled).

  • CVE-2024-25419HigFeb 11, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.

  • CVE-2024-25418HigFeb 11, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.

  • CVE-2024-25417HigFeb 11, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.

  • CVE-2023-47020HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed…

  • CVE-2024-24469HigFeb 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.