VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 408 of 479
  • CVE-2021-3957MedNov 19, 2021
    risk 0.21cvss 4.3epss 0.00

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-41273MedNov 17, 2021
    risk 0.21cvss 4.3epss 0.00

    Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node…

  • CVE-2021-3932MedNov 13, 2021
    risk 0.21cvss 4.3epss 0.00

    twill is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3931MedNov 13, 2021
    risk 0.21cvss 4.3epss 0.00

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3921MedNov 13, 2021
    risk 0.21cvss 4.3epss 0.00

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-41176MedOct 25, 2021
    risk 0.21cvss 4.3epss 0.01

    Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This…

  • CVE-2021-3729MedAug 23, 2021
    risk 0.21cvss 4.3epss 0.00

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2020-36389MedJun 17, 2021
    risk 0.21cvss 4.3epss 0.01

    In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.

  • CVE-2021-25930MedMay 20, 2021
    risk 0.21cvss 4.3epss 0.01

    In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no…

  • CVE-2021-21641MedApr 7, 2021
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.

  • CVE-2021-21027MedFeb 11, 2021
    risk 0.21cvss 4.3epss 0.02

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated…

  • CVE-2020-10734LowFeb 11, 2021
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.

  • CVE-2020-2303MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.

  • CVE-2020-16252MedAug 5, 2020
    risk 0.21cvss 4.3epss 0.00

    The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.

  • CVE-2020-8166MedJul 2, 2020
    risk 0.21cvss 4.3epss 0.02

    A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

  • CVE-2020-2203MedJul 2, 2020
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.

  • CVE-2020-2186MedMay 6, 2020
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.

  • CVE-2020-2147MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2020-2141MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.

  • CVE-2019-12246MedFeb 19, 2020
    risk 0.21cvss 4.3epss 0.01

    SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools.