CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 408 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3957 | Med | 0.21 | 4.3 | 0.00 | Nov 19, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-41273 | Med | 0.21 | 4.3 | 0.00 | Nov 17, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node… | ||
| CVE-2021-3932 | Med | 0.21 | 4.3 | 0.00 | Nov 13, 2021 | twill is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-3931 | Med | 0.21 | 4.3 | 0.00 | Nov 13, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-3921 | Med | 0.21 | 4.3 | 0.00 | Nov 13, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-41176 | Med | 0.21 | 4.3 | 0.01 | Oct 25, 2021 | Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This… | ||
| CVE-2021-3729 | Med | 0.21 | 4.3 | 0.00 | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2020-36389 | Med | 0.21 | 4.3 | 0.01 | Jun 17, 2021 | In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF. | ||
| CVE-2021-25930 | Med | 0.21 | 4.3 | 0.01 | May 20, 2021 | In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no… | ||
| CVE-2021-21641 | Med | 0.21 | 4.3 | 0.01 | Apr 7, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds. | ||
| CVE-2021-21027 | Med | 0.21 | 4.3 | 0.02 | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated… | ||
| CVE-2020-10734 | Low | 0.21 | 3.3 | 0.00 | Feb 11, 2021 | A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable. | ||
| CVE-2020-2303 | Med | 0.21 | 4.3 | 0.01 | Nov 4, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials. | ||
| CVE-2020-16252 | Med | 0.21 | 4.3 | 0.00 | Aug 5, 2020 | The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF. | ||
| CVE-2020-8166 | Med | 0.21 | 4.3 | 0.02 | Jul 2, 2020 | A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token. | ||
| CVE-2020-2203 | Med | 0.21 | 4.3 | 0.01 | Jul 2, 2020 | A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs. | ||
| CVE-2020-2186 | Med | 0.21 | 4.3 | 0.01 | May 6, 2020 | A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances. | ||
| CVE-2020-2147 | Med | 0.21 | 4.3 | 0.01 | Mar 9, 2020 | A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials. | ||
| CVE-2020-2141 | Med | 0.21 | 4.3 | 0.01 | Mar 9, 2020 | A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce. | ||
| CVE-2019-12246 | Med | 0.21 | 4.3 | 0.01 | Feb 19, 2020 | SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools. |
- risk 0.21cvss 4.3epss 0.00
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.21cvss 4.3epss 0.00
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node…
- risk 0.21cvss 4.3epss 0.00
twill is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.21cvss 4.3epss 0.00
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.21cvss 4.3epss 0.00
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.21cvss 4.3epss 0.01
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This…
- risk 0.21cvss 4.3epss 0.00
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.21cvss 4.3epss 0.01
In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
- risk 0.21cvss 4.3epss 0.01
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no…
- risk 0.21cvss 4.3epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.
- risk 0.21cvss 4.3epss 0.02
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated…
- risk 0.21cvss 3.3epss 0.00
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
- risk 0.21cvss 4.3epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.
- risk 0.21cvss 4.3epss 0.00
The Field Test gem 0.2.0 through 0.3.2 for Ruby allows CSRF.
- risk 0.21cvss 4.3epss 0.02
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
- risk 0.21cvss 4.3epss 0.01
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.
- risk 0.21cvss 4.3epss 0.01
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.
- risk 0.21cvss 4.3epss 0.01
A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
- risk 0.21cvss 4.3epss 0.01
A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.
- risk 0.21cvss 4.3epss 0.01
SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools.