CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 433 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-1522 | Hig | 0.00 | 8.8 | 0.00 | Mar 30, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an… | ||
| CVE-2024-28195 | Hig | 0.00 | 8.1 | 0.00 | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the API and login flow against Cross-Site Request Forgery (CSRF). Attackers can use this to execute CSRF attacks on victims, allowing them to retrieve, modify or… | ||
| CVE-2024-2215 | Med | 0.00 | 6.1 | 0.00 | Mar 6, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build… | ||
| CVE-2024-24819 | Med | 0.00 | 5.3 | 0.00 | Feb 9, 2024 | icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This… | ||
| CVE-2024-24820 | Hig | 0.00 | 8.3 | 0.00 | Feb 9, 2024 | Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the… | ||
| CVE-2024-23831 | Hig | 0.00 | 7.5 | 0.00 | Feb 2, 2024 | LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This… | ||
| CVE-2018-25096 | Med | 0.00 | 4.3 | 0.00 | Dec 30, 2023 | A vulnerability was found in MdAlAmin-aol Own Health Record 0.1-alpha/0.2-alpha/0.3-alpha/0.3.1-alpha. It has been rated as problematic. This issue affects some unknown processing of the file includes/logout.php. The manipulation leads to cross-site request forgery. The attack… | ||
| CVE-2023-49076 | Med | 0.00 | 4.3 | 0.00 | Nov 30, 2023 | Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5. | ||
| CVE-2023-5902 | Med | 0.00 | 4.3 | 0.00 | Nov 7, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | ||
| CVE-2023-5900 | Low | 0.00 | 3.5 | 0.00 | Nov 7, 2023 | Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | ||
| CVE-2023-5899 | Hig | 0.00 | 8.8 | 0.00 | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | ||
| CVE-2023-5898 | Hig | 0.00 | 8.8 | 0.00 | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | ||
| CVE-2023-5897 | Hig | 0.00 | 8.8 | 0.00 | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1. | ||
| CVE-2023-5893 | Hig | 0.00 | 8.8 | 0.00 | Nov 1, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | ||
| CVE-2023-5687 | Hig | 0.00 | 8.8 | 0.00 | Oct 20, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3. | ||
| CVE-2023-5626 | Hig | 0.00 | 8.8 | 0.00 | Oct 18, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16. | ||
| CVE-2023-5498 | Med | 0.00 | 4.3 | 0.00 | Oct 10, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47. | ||
| CVE-2023-40172 | Med | 0.00 | 6.5 | 0.00 | Aug 18, 2023 | Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they… | ||
| CVE-2023-38999 | Med | 0.00 | 6.5 | 0.00 | Aug 9, 2023 | A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | ||
| CVE-2023-3627 | Hig | 0.00 | 8.8 | 0.00 | Jul 11, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1. |
- risk 0.00cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an…
- risk 0.00cvss 8.1epss 0.00
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the API and login flow against Cross-Site Request Forgery (CSRF). Attackers can use this to execute CSRF attacks on victims, allowing them to retrieve, modify or…
- risk 0.00cvss 6.1epss 0.00
A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build…
- risk 0.00cvss 5.3epss 0.00
icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This…
- risk 0.00cvss 8.3epss 0.00
Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the…
- risk 0.00cvss 7.5epss 0.00
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in MdAlAmin-aol Own Health Record 0.1-alpha/0.2-alpha/0.3-alpha/0.3.1-alpha. It has been rated as problematic. This issue affects some unknown processing of the file includes/logout.php. The manipulation leads to cross-site request forgery. The attack…
- risk 0.00cvss 4.3epss 0.00
Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5.
- risk 0.00cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- risk 0.00cvss 3.5epss 0.00
Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.
- risk 0.00cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47.
- risk 0.00cvss 6.5epss 0.00
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they…
- risk 0.00cvss 6.5epss 0.00
A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.