CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,651)
page 41 of 483| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36546 | Hig | 0.57 | 8.8 | 0.01 | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php. | ||
| CVE-2022-31773 | Hig | 0.57 | 8.8 | 0.00 | Aug 26, 2022 | IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 228357. | ||
| CVE-2022-36379 | Hig | 0.57 | 8.8 | 0.01 | Aug 23, 2022 | Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress. | ||
| CVE-2022-29468 | Hig | 0.57 | 8.8 | 0.02 | Aug 22, 2022 | A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability. | ||
| CVE-2022-36579 | Hig | 0.57 | 8.8 | 0.00 | Aug 19, 2022 | Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF). | ||
| CVE-2022-36577 | Hig | 0.57 | 8.8 | 0.00 | Aug 19, 2022 | An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin. | ||
| CVE-2022-36225 | Hig | 0.57 | 8.8 | 0.00 | Aug 19, 2022 | EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add. | ||
| CVE-2022-36224 | Hig | 0.57 | 8.8 | 0.00 | Aug 19, 2022 | XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF). | ||
| CVE-2022-36312 | Hig | 0.57 | 8.8 | 0.00 | Aug 16, 2022 | Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models. | ||
| CVE-2022-38359 | Hig | 0.57 | 8.8 | 0.00 | Aug 15, 2022 | Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authenticated user to the URL https:///module/admin_u… | ||
| CVE-2022-2381 | Hig | 0.57 | 8.8 | 0.01 | Aug 15, 2022 | The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack | ||
| CVE-2022-34158 | Hig | 0.57 | 8.8 | 0.01 | Aug 4, 2022 | A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify… | ||
| CVE-2022-34937 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2022 | Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code. | ||
| CVE-2022-34161 | Hig | 0.57 | 8.8 | 0.00 | Aug 1, 2022 | IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 229331. | ||
| CVE-2022-2245 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2022 | The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks | ||
| CVE-2022-2184 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2022 | The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server. | ||
| CVE-2022-36920 | Hig | 0.57 | 8.8 | 0.01 | Jul 27, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||
| CVE-2022-35286 | Hig | 0.57 | 8.8 | 0.00 | Jul 26, 2022 | IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814. | ||
| CVE-2022-35285 | Hig | 0.57 | 8.8 | 0.00 | Jul 25, 2022 | IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812. | ||
| CVE-2022-2443 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2022 | The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/freemind-wp-browser.php file. This makes it possible for… |
- risk 0.57cvss 8.8epss 0.01
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.
- risk 0.57cvss 8.8epss 0.00
IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 228357.
- risk 0.57cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.
- risk 0.57cvss 8.8epss 0.02
A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
- risk 0.57cvss 8.8epss 0.00
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
- risk 0.57cvss 8.8epss 0.00
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
- risk 0.57cvss 8.8epss 0.00
XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.00
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
- risk 0.57cvss 8.8epss 0.00
Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authenticated user to the URL https:///module/admin_u…
- risk 0.57cvss 8.8epss 0.01
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack
- risk 0.57cvss 8.8epss 0.01
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify…
- risk 0.57cvss 8.8epss 0.01
Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.
- risk 0.57cvss 8.8epss 0.00
IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 229331.
- risk 0.57cvss 8.8epss 0.01
The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
- risk 0.57cvss 8.8epss 0.01
The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-side templates. This can be abused by attackers, via a Cross-Site Request Forgery attack to run arbitrary code on the server.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- risk 0.57cvss 8.8epss 0.00
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814.
- risk 0.57cvss 8.8epss 0.00
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812.
- risk 0.57cvss 8.8epss 0.01
The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/freemind-wp-browser.php file. This makes it possible for…