VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 384 of 479
  • CVE-2021-24586MedSep 13, 2021
    risk 0.28cvss 4.3epss 0.00

    The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned…

  • CVE-2021-24431MedSep 13, 2021
    risk 0.28cvss 4.3epss 0.00

    The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set…

  • CVE-2021-27557MedAug 31, 2021
    risk 0.28cvss 4.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.

  • CVE-2021-32991MedAug 30, 2021
    risk 0.28cvss 4.3epss 0.00

    Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.

  • CVE-2021-28070MedAug 25, 2021
    risk 0.28cvss 4.3epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.

  • CVE-2021-23431MedAug 24, 2021
    risk 0.28cvss 5.4epss 0.00

    The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.

  • CVE-2021-24380MedAug 16, 2021
    risk 0.28cvss 4.3epss 0.00

    The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.

  • CVE-2020-20989MedAug 12, 2021
    risk 0.28cvss 4.3epss 0.00

    A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.

  • CVE-2021-36543MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

  • CVE-2021-36542MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

  • CVE-2021-35343MedAug 3, 2021
    risk 0.28cvss 4.3epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

  • CVE-2021-20786MedJul 30, 2021
    risk 0.28cvss 4.3epss 0.00

    Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0)…

  • CVE-2021-20580MedJun 29, 2021
    risk 0.28cvss 4.3epss 0.00

    IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.

  • CVE-2021-34547MedJun 10, 2021
    risk 0.28cvss 4.3epss 0.00

    PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.

  • CVE-2020-35972MedJun 3, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.

  • CVE-2020-24740MedMay 18, 2021
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage

  • CVE-2021-24251MedMay 6, 2021
    risk 0.28cvss 4.3epss 0.00

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from…

  • CVE-2021-21644MedApr 21, 2021
    risk 0.28cvss 5.4epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.

  • CVE-2021-24172MedApr 5, 2021
    risk 0.28cvss 4.3epss 0.00

    The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .

  • CVE-2021-26216MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.00

    SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.