VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,651)

page 41 of 483
  • CVE-2022-36546HigAug 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.

  • CVE-2022-31773HigAug 26, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 228357.

  • CVE-2022-36379HigAug 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.

  • CVE-2022-29468HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.02

    A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

  • CVE-2022-36579HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2022-36577HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.

  • CVE-2022-36225HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.

  • CVE-2022-36224HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2022-36312HigAug 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.

  • CVE-2022-38359HigAug 15, 2022
    risk 0.57cvss 8.8epss 0.00

    Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authenticated user to the URL https:///module/admin_u…

  • CVE-2022-2381HigAug 15, 2022
    risk 0.57cvss 8.8epss 0.01

    The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack

  • CVE-2022-34158HigAug 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify…

  • CVE-2022-34937HigAug 3, 2022
    risk 0.57cvss 8.8epss 0.01

    Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.

  • CVE-2022-34161HigAug 1, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 229331.

  • CVE-2022-2245HigAug 1, 2022
    risk 0.57cvss 8.8epss 0.01

    The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks

  • CVE-2022-2184HigAug 1, 2022
    risk 0.57cvss 8.8epss 0.01

    The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.

  • CVE-2022-36920HigJul 27, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-35286HigJul 26, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814.

  • CVE-2022-35285HigJul 25, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812.

  • CVE-2022-2443HigJul 18, 2022
    risk 0.57cvss 8.8epss 0.01

    The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/freemind-wp-browser.php file. This makes it possible for…