VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,651)

page 33 of 483
  • CVE-2022-2441HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they…

  • CVE-2023-45907HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.

  • CVE-2023-45906HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.

  • CVE-2023-45905HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.

  • CVE-2023-45904HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.

  • CVE-2023-45903HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.

  • CVE-2023-45902HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.

  • CVE-2023-45901HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.

  • CVE-2023-43118HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API.

  • CVE-2023-43149HigOct 12, 2023
    risk 0.57cvss 8.8epss 0.01

    SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.

  • CVE-2023-43147HigOct 12, 2023
    risk 0.57cvss 8.8epss 0.00

    PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.

  • CVE-2023-4837HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.00

    SmodBIP is vulnerable to Cross-Site Request Forgery, that could be used to induce logged in users to perform unintended actions, including creation of additional accounts with administrative privileges. This issue affects all versions of SmodBIP. SmodBIP is no longer maintained…

  • CVE-2023-44811HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the admin Password Change Function.

  • CVE-2023-41086HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross-site request forgery (CSRF) vulnerability exists in FURUNO SYSTEMS wireless LAN access point devices. If a user views a malicious page while logged in, unintended operations may be performed. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and…

  • CVE-2023-41452HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.

  • CVE-2023-35793HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.

  • CVE-2023-43278HigSep 25, 2023
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.

  • CVE-2023-42321HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.

  • CVE-2023-43500HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.

  • CVE-2023-42270HigSep 15, 2023
    risk 0.57cvss 8.8epss 0.00

    Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).