VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 386 of 479
  • CVE-2020-15400MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.00

    CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

  • CVE-2019-20415MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.01

    Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0.

  • CVE-2019-20411MedJun 29, 2020
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.

  • CVE-2016-11055MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11,…

  • CVE-2020-4199MedMar 18, 2020
    risk 0.28cvss 4.3epss 0.00

    IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910.

  • CVE-2020-10504MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.

  • CVE-2020-10503MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.

  • CVE-2020-10502MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.

  • CVE-2020-10500MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to reply to any ticket, given the id, via a crafted request.

  • CVE-2020-10499MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.

  • CVE-2020-10496MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article, given the id, via a crafted request.

  • CVE-2020-10495MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the id, via a crafted request.

  • CVE-2020-10494MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.

  • CVE-2020-10493MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.

  • CVE-2020-10492MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a crafted request.

  • CVE-2020-10491MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a department via a crafted request.

  • CVE-2020-10490MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a department via a crafted request.

  • CVE-2020-10489MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted request.

  • CVE-2020-10488MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a news article via a crafted request.

  • CVE-2020-10487MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.01

    CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.