VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,651)

page 39 of 483
  • CVE-2022-3240HigNov 15, 2022
    risk 0.57cvss 8.8epss 0.01

    The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing nonce validation on the FollowMeIgniteSocialMedia_options_page() function. This makes it possible for unauthenticated attackers…

  • CVE-2022-35613HigNov 15, 2022
    risk 0.57cvss 8.8epss 0.00

    Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF).

  • CVE-2022-44387HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.

  • CVE-2022-43323HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.

  • CVE-2022-43031HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.01

    DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.

  • CVE-2022-3537HigNov 7, 2022
    risk 0.57cvss 8.8epss 0.01

    The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP

  • CVE-2022-3536HigNov 7, 2022
    risk 0.57cvss 8.8epss 0.01

    The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can…

  • CVE-2022-20961HigNov 4, 2022
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due…

  • CVE-2022-30608HigNov 3, 2022
    risk 0.57cvss 8.8epss 0.00

    "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295.

  • CVE-2022-42751HigNov 3, 2022
    risk 0.57cvss 8.8epss 0.00

    CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

  • CVE-2022-3852HigNov 3, 2022
    risk 0.57cvss 8.8epss 0.01

    The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify…

  • CVE-2022-3776HigNov 3, 2022
    risk 0.57cvss 8.8epss 0.01

    The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as…

  • CVE-2022-40291HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.00

    The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack their account and create other admin accounts.

  • CVE-2022-43340HigOct 27, 2022
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.

  • CVE-2022-41996HigOct 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.

  • CVE-2022-42199HigOct 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.

  • CVE-2022-41500HigOct 18, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.

  • CVE-2022-42070HigOct 14, 2022
    risk 0.57cvss 8.8epss 0.00

    Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2022-41475HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.00

    RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account.

  • CVE-2022-34020HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts.