CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 387 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10486 | Med | 0.28 | 4.3 | 0.00 | Mar 12, 2020 | CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request. | ||
| CVE-2020-10485 | Med | 0.28 | 4.3 | 0.00 | Mar 12, 2020 | CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request. | ||
| CVE-2020-10484 | Med | 0.28 | 4.3 | 0.00 | Mar 12, 2020 | CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request. | ||
| CVE-2020-10483 | Med | 0.28 | 4.3 | 0.00 | Mar 12, 2020 | CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request. | ||
| CVE-2020-10482 | Med | 0.28 | 4.3 | 0.00 | Mar 12, 2020 | CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request. | ||
| CVE-2020-10481 | Med | 0.28 | 4.3 | 0.00 | Mar 12, 2020 | CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted request. | ||
| CVE-2020-10480 | Med | 0.28 | 4.3 | 0.01 | Mar 12, 2020 | CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request. | ||
| CVE-2020-10479 | Med | 0.28 | 4.3 | 0.00 | Mar 12, 2020 | CSRF in admin/add-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new news article via a crafted request. | ||
| CVE-2019-16107 | Med | 0.28 | 4.3 | 0.00 | Mar 11, 2020 | Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments. | ||
| CVE-2020-6206 | Med | 0.28 | 4.3 | 0.00 | Mar 10, 2020 | SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery. | ||
| CVE-2019-4726 | Med | 0.28 | 4.3 | 0.00 | Feb 26, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363. | ||
| CVE-2019-20099 | Med | 0.28 | 4.3 | 0.01 | Feb 12, 2020 | The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the… | ||
| CVE-2019-20098 | Med | 0.28 | 4.3 | 0.01 | Feb 12, 2020 | The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the… | ||
| CVE-2019-19668 | Med | 0.28 | 4.3 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html. | ||
| CVE-2019-19666 | Med | 0.28 | 4.3 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can create/update event notices via RAPR/EventNoticesSet.html. | ||
| CVE-2019-20405 | Med | 0.28 | 4.3 | 0.01 | Feb 6, 2020 | The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability. | ||
| CVE-2020-7210 | Med | 0.28 | 4.3 | 0.01 | Jan 23, 2020 | Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts. | ||
| CVE-2020-5397 | Med | 0.28 | 5.3 | 0.02 | Jan 17, 2020 | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight… | ||
| CVE-2020-5501 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2020 | phpBB 3.2.8 allows a CSRF attack that can modify a group avatar. | ||
| CVE-2019-20077 | Med | 0.28 | 4.3 | 0.00 | Jan 5, 2020 | The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability. |
- risk 0.28cvss 4.3epss 0.00
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request.
- risk 0.28cvss 4.3epss 0.00
CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request.
- risk 0.28cvss 4.3epss 0.00
CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request.
- risk 0.28cvss 4.3epss 0.00
CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.
- risk 0.28cvss 4.3epss 0.00
CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request.
- risk 0.28cvss 4.3epss 0.00
CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted request.
- risk 0.28cvss 4.3epss 0.01
CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request.
- risk 0.28cvss 4.3epss 0.00
CSRF in admin/add-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new news article via a crafted request.
- risk 0.28cvss 4.3epss 0.00
Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.
- risk 0.28cvss 4.3epss 0.00
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.
- risk 0.28cvss 4.3epss 0.00
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363.
- risk 0.28cvss 4.3epss 0.01
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the…
- risk 0.28cvss 4.3epss 0.01
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the…
- risk 0.28cvss 4.3epss 0.00
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.
- risk 0.28cvss 4.3epss 0.00
A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can create/update event notices via RAPR/EventNoticesSet.html.
- risk 0.28cvss 4.3epss 0.01
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
- risk 0.28cvss 4.3epss 0.01
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
- risk 0.28cvss 5.3epss 0.02
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight…
- risk 0.28cvss 4.3epss 0.00
phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
- risk 0.28cvss 4.3epss 0.00
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability.