VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 387 of 479
  • CVE-2020-10486MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request.

  • CVE-2020-10485MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request.

  • CVE-2020-10484MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request.

  • CVE-2020-10483MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.

  • CVE-2020-10482MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request.

  • CVE-2020-10481MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted request.

  • CVE-2020-10480MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.01

    CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request.

  • CVE-2020-10479MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.00

    CSRF in admin/add-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new news article via a crafted request.

  • CVE-2019-16107MedMar 11, 2020
    risk 0.28cvss 4.3epss 0.00

    Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.

  • CVE-2020-6206MedMar 10, 2020
    risk 0.28cvss 4.3epss 0.00

    SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

  • CVE-2019-4726MedFeb 26, 2020
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363.

  • CVE-2019-20099MedFeb 12, 2020
    risk 0.28cvss 4.3epss 0.01

    The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the…

  • CVE-2019-20098MedFeb 12, 2020
    risk 0.28cvss 4.3epss 0.01

    The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the…

  • CVE-2019-19668MedFeb 10, 2020
    risk 0.28cvss 4.3epss 0.00

    A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.

  • CVE-2019-19666MedFeb 10, 2020
    risk 0.28cvss 4.3epss 0.00

    A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can create/update event notices via RAPR/EventNoticesSet.html.

  • CVE-2019-20405MedFeb 6, 2020
    risk 0.28cvss 4.3epss 0.01

    The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.

  • CVE-2020-7210MedJan 23, 2020
    risk 0.28cvss 4.3epss 0.01

    Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.

  • CVE-2020-5397MedJan 17, 2020
    risk 0.28cvss 5.3epss 0.02

    Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight…

  • CVE-2020-5501MedJan 15, 2020
    risk 0.28cvss 4.3epss 0.00

    phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.

  • CVE-2019-20077MedJan 5, 2020
    risk 0.28cvss 4.3epss 0.00

    The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability.