VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 388 of 479
  • CVE-2019-4736MedDec 20, 2019
    risk 0.28cvss 4.3epss 0.00

    IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172706.

  • CVE-2019-4231MedDec 20, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.

  • CVE-2019-16569MedDec 17, 2019
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Mantis Plugin 0.26 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.

  • CVE-2019-4095MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.00

    IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158015.

  • CVE-2019-16752MedDec 4, 2019
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can…

  • CVE-2013-6365MedNov 5, 2019
    risk 0.28cvss 5.3epss 0.01

    Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

  • CVE-2019-10456MedOct 16, 2019
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2015-9418MedSep 26, 2019
    risk 0.28cvss 4.3epss 0.01

    The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.

  • CVE-2019-10408MedSep 25, 2019
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.

  • CVE-2019-13920MedSep 13, 2019
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not protected against Cross Site Request Forgery (CSRF) attacks. The security vulnerability could be exploited by an attacker that is able to…

  • CVE-2019-8447MedAug 23, 2019
    risk 0.28cvss 4.3epss 0.01

    The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.

  • CVE-2019-14999MedAug 23, 2019
    risk 0.28cvss 4.3epss 0.01

    The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on…

  • CVE-2019-11588MedAug 23, 2019
    risk 0.28cvss 4.3epss 0.01

    The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.

  • CVE-2019-11586MedAug 23, 2019
    risk 0.28cvss 4.3epss 0.01

    The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.

  • CVE-2014-10382MedAug 22, 2019
    risk 0.28cvss 4.3epss 0.01

    The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.

  • CVE-2019-14682MedAug 8, 2019
    risk 0.28cvss 4.3epss 0.01

    The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF.

  • CVE-2019-10388MedAug 7, 2019
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.

  • CVE-2019-10331MedJun 11, 2019
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2019-10321MedMay 31, 2019
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained…

  • CVE-2018-1790MedMay 10, 2019
    risk 0.28cvss 4.3epss 0.01

    IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 148944.