CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,651)
page 39 of 483| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3240 | Hig | 0.57 | 8.8 | 0.01 | Nov 15, 2022 | The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing nonce validation on the FollowMeIgniteSocialMedia_options_page() function. This makes it possible for unauthenticated attackers… | ||
| CVE-2022-35613 | Hig | 0.57 | 8.8 | 0.00 | Nov 15, 2022 | Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF). | ||
| CVE-2022-44387 | Hig | 0.57 | 8.8 | 0.00 | Nov 14, 2022 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module. | ||
| CVE-2022-43323 | Hig | 0.57 | 8.8 | 0.00 | Nov 14, 2022 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module. | ||
| CVE-2022-43031 | Hig | 0.57 | 8.8 | 0.01 | Nov 9, 2022 | DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords. | ||
| CVE-2022-3537 | Hig | 0.57 | 8.8 | 0.01 | Nov 7, 2022 | The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP | ||
| CVE-2022-3536 | Hig | 0.57 | 8.8 | 0.01 | Nov 7, 2022 | The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can… | ||
| CVE-2022-20961 | Hig | 0.57 | 8.8 | 0.00 | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due… | ||
| CVE-2022-30608 | Hig | 0.57 | 8.8 | 0.00 | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295. | ||
| CVE-2022-42751 | Hig | 0.57 | 8.8 | 0.00 | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions. | ||
| CVE-2022-3852 | Hig | 0.57 | 8.8 | 0.01 | Nov 3, 2022 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify… | ||
| CVE-2022-3776 | Hig | 0.57 | 8.8 | 0.01 | Nov 3, 2022 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as… | ||
| CVE-2022-40291 | Hig | 0.57 | 8.8 | 0.00 | Oct 31, 2022 | The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack their account and create other admin accounts. | ||
| CVE-2022-43340 | Hig | 0.57 | 8.8 | 0.00 | Oct 27, 2022 | A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users. | ||
| CVE-2022-41996 | Hig | 0.57 | 8.8 | 0.01 | Oct 27, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation. | ||
| CVE-2022-42199 | Hig | 0.57 | 8.8 | 0.01 | Oct 20, 2022 | Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List. | ||
| CVE-2022-41500 | Hig | 0.57 | 8.8 | 0.00 | Oct 18, 2022 | EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components. | ||
| CVE-2022-42070 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2022 | Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF). | ||
| CVE-2022-41475 | Hig | 0.57 | 8.8 | 0.00 | Oct 13, 2022 | RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account. | ||
| CVE-2022-34020 | Hig | 0.57 | 8.8 | 0.00 | Oct 13, 2022 | Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts. |
- risk 0.57cvss 8.8epss 0.01
The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing nonce validation on the FollowMeIgniteSocialMedia_options_page() function. This makes it possible for unauthenticated attackers…
- risk 0.57cvss 8.8epss 0.00
Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.00
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.
- risk 0.57cvss 8.8epss 0.00
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.
- risk 0.57cvss 8.8epss 0.01
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.
- risk 0.57cvss 8.8epss 0.01
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP
- risk 0.57cvss 8.8epss 0.01
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate path given via user input, allowing any authenticated users like subscriber to perform PHAR deserialization attacks when they can…
- risk 0.57cvss 8.8epss 0.00
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due…
- risk 0.57cvss 8.8epss 0.00
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295.
- risk 0.57cvss 8.8epss 0.00
CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.
- risk 0.57cvss 8.8epss 0.01
The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify…
- risk 0.57cvss 8.8epss 0.01
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as…
- risk 0.57cvss 8.8epss 0.00
The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack their account and create other admin accounts.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.
- risk 0.57cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.
- risk 0.57cvss 8.8epss 0.01
Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.
- risk 0.57cvss 8.8epss 0.00
EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components.
- risk 0.57cvss 8.8epss 0.00
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.00
RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account.
- risk 0.57cvss 8.8epss 0.00
Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts.