VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 385 of 479
  • CVE-2021-26215MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.00

    SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.

  • CVE-2021-24133MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.00

    Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacker's account.

  • CVE-2020-24982MedMar 15, 2021
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.

  • CVE-2020-28644MedFeb 9, 2021
    risk 0.28cvss 4.3epss 0.00

    The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.

  • CVE-2020-4827MedFeb 4, 2021
    risk 0.28cvss 4.3epss 0.00

    IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189841.

  • CVE-2020-4826MedFeb 4, 2021
    risk 0.28cvss 4.3epss 0.00

    IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189840.

  • CVE-2020-25950MedJan 8, 2021
    risk 0.28cvss 4.3epss 0.00

    Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.

  • CVE-2020-35778MedDec 30, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.

  • CVE-2020-28040MedNov 2, 2020
    risk 0.28cvss 4.3epss 0.01

    WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

  • CVE-2020-24847MedOct 23, 2020
    risk 0.28cvss 4.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this…

  • CVE-2020-2296MedOct 8, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.

  • CVE-2020-25262MedOct 8, 2020
    risk 0.28cvss 4.3epss 0.01

    PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.

  • CVE-2020-2281MedSep 23, 2020
    risk 0.28cvss 5.4epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock, and reset resources.

  • CVE-2020-2273MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2020-4526MedSep 15, 2020
    risk 0.28cvss 4.3epss 0.00

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 182436.

  • CVE-2020-16610MedAug 28, 2020
    risk 0.28cvss 4.3epss 0.00

    Hoosk Codeigniter CMS before 1.7.2 is affected by a Cross Site Request Forgery (CSRF). When an attacker induces authenticated admin user to a malicious web page, any accounts can be deleted without admin user's intention.

  • CVE-2020-5621MedAug 28, 2020
    risk 0.28cvss 4.3epss 0.01

    Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier) allow remote attackers to hijack the authentication of administrators and alter the settings of the…

  • CVE-2020-4170MedAug 24, 2020
    risk 0.28cvss 4.3epss 0.00

    IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174406.

  • CVE-2020-2237MedAug 12, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attackers to rebuild a project at a previous git revision.

  • CVE-2020-2215MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified username and password.