CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,651)
page 34 of 483| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40868 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2023 | Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions. | ||
| CVE-2023-4916 | Hig | 0.57 | 8.8 | 0.00 | Sep 13, 2023 | The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated attackers to… | ||
| CVE-2023-40953 | Hig | 0.57 | 8.8 | 0.00 | Sep 8, 2023 | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). | ||
| CVE-2015-1391 | Hig | 0.57 | 8.8 | 0.00 | Sep 5, 2023 | Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism. | ||
| CVE-2023-40341 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job. | ||
| CVE-2023-40336 | Hig | 0.57 | 8.8 | 0.00 | Aug 16, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders. | ||
| CVE-2020-24922 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2023 | Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file. | ||
| CVE-2020-23595 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2023 | Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint. | ||
| CVE-2023-4277 | Hig | 0.57 | 8.8 | 0.00 | Aug 10, 2023 | The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email… | ||
| CVE-2023-4276 | Hig | 0.57 | 8.8 | 0.00 | Aug 10, 2023 | The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email… | ||
| CVE-2023-38348 | Hig | 0.57 | 8.8 | 0.00 | Aug 9, 2023 | A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1. | ||
| CVE-2023-31452 | Hig | 0.57 | 8.8 | 0.01 | Aug 9, 2023 | A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious… | ||
| CVE-2023-38759 | Hig | 0.57 | 8.8 | 0.00 | Aug 8, 2023 | Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html,… | ||
| CVE-2023-4047 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2023 | A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. | ||
| CVE-2023-33534 | Hig | 0.57 | 8.8 | 0.00 | Jul 31, 2023 | A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeover user accounts via sending a crafted POST request to /goform/goform_set_cmd_process. | ||
| CVE-2022-43710 | Hig | 0.57 | 8.8 | 0.00 | Jul 26, 2023 | Interactive Forms (IAF) in GX Software XperienCentral versions 10.31.0 until 10.33.0 was vulnerable to cross site request forgery (CSRF) because the unique token could be deduced using the names of all input fields. | ||
| CVE-2022-30280 | Hig | 0.57 | 8.8 | 0.00 | Jul 24, 2023 | /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a… | ||
| CVE-2023-37650 | Hig | 0.57 | 8.8 | 0.01 | Jul 20, 2023 | A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands. | ||
| CVE-2023-38349 | — | Hig | 0.57 | 8.8 | 0.00 | Jul 15, 2023 | PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26. | |
| CVE-2023-37562 | Hig | 0.57 | 8.8 | 0.00 | Jul 13, 2023 | Cross-site request forgery (CSRF) vulnerability in exists in WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 and earlier. If a user views a malicious page while logged in, unintended operations may be performed. |
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions.
- risk 0.57cvss 8.8epss 0.00
The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function. This makes it possible for unauthenticated attackers to…
- risk 0.57cvss 8.8epss 0.00
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.00
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job.
- risk 0.57cvss 8.8epss 0.00
A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders.
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.
- risk 0.57cvss 8.8epss 0.00
The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email…
- risk 0.57cvss 8.8epss 0.00
The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email…
- risk 0.57cvss 8.8epss 0.00
A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious…
- risk 0.57cvss 8.8epss 0.00
Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html,…
- risk 0.57cvss 8.8epss 0.01
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeover user accounts via sending a crafted POST request to /goform/goform_set_cmd_process.
- risk 0.57cvss 8.8epss 0.00
Interactive Forms (IAF) in GX Software XperienCentral versions 10.31.0 until 10.33.0 was vulnerable to cross site request forgery (CSRF) because the unique token could be deduced using the names of all input fields.
- risk 0.57cvss 8.8epss 0.00
/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a…
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
- risk 0.57cvss 8.8epss 0.00
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
- risk 0.57cvss 8.8epss 0.00
Cross-site request forgery (CSRF) vulnerability in exists in WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 and earlier. If a user views a malicious page while logged in, unintended operations may be performed.