VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 433 of 479
  • CVE-2024-1522HigMar 30, 2024
    risk 0.00cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an…

  • CVE-2024-28195HigMar 13, 2024
    risk 0.00cvss 8.1epss 0.00

    your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the API and login flow against Cross-Site Request Forgery (CSRF). Attackers can use this to execute CSRF attacks on victims, allowing them to retrieve, modify or…

  • CVE-2024-2215MedMar 6, 2024
    risk 0.00cvss 6.1epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build…

  • CVE-2024-24819MedFeb 9, 2024
    risk 0.00cvss 5.3epss 0.00

    icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This…

  • CVE-2024-24820HigFeb 9, 2024
    risk 0.00cvss 8.3epss 0.00

    Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the…

  • CVE-2024-23831HigFeb 2, 2024
    risk 0.00cvss 7.5epss 0.00

    LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This…

  • CVE-2018-25096MedDec 30, 2023
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in MdAlAmin-aol Own Health Record 0.1-alpha/0.2-alpha/0.3-alpha/0.3.1-alpha. It has been rated as problematic. This issue affects some unknown processing of the file includes/logout.php. The manipulation leads to cross-site request forgery. The attack…

  • CVE-2023-49076MedNov 30, 2023
    risk 0.00cvss 4.3epss 0.00

    Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.

  • CVE-2023-5902MedNov 7, 2023
    risk 0.00cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5900LowNov 7, 2023
    risk 0.00cvss 3.5epss 0.00

    Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5899HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5898HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5897HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.

  • CVE-2023-5893HigNov 1, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-5687HigOct 20, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.

  • CVE-2023-5626HigOct 18, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.

  • CVE-2023-5498MedOct 10, 2023
    risk 0.00cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47.

  • CVE-2023-40172MedAug 18, 2023
    risk 0.00cvss 6.5epss 0.00

    Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they…

  • CVE-2023-38999MedAug 9, 2023
    risk 0.00cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-3627HigJul 11, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.