CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 434 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30607 | Med | 0.00 | 5.0 | 0.00 | Jul 5, 2023 | icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is… | ||
| CVE-2023-3075 | Med | 0.00 | 6.5 | 0.00 | Jun 2, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8. | ||
| CVE-2023-2552 | Hig | 0.00 | 8.8 | 0.00 | May 5, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1. | ||
| CVE-2023-30616 | Med | 0.00 | 6.5 | 0.00 | Apr 20, 2023 | Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to… | ||
| CVE-2023-28848 | Med | 0.00 | 4.8 | 0.00 | Apr 4, 2023 | user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request… | ||
| CVE-2023-0642 | Med | 0.00 | 6.5 | 0.00 | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0. | ||
| CVE-2023-22472 | Med | 0.00 | 5.3 | 0.00 | Jan 9, 2023 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they click on a malicious deep link on a Windows computer. (e.g. in… | ||
| CVE-2022-4766 | Med | 0.00 | 4.3 | 0.00 | Dec 27, 2022 | A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading… | ||
| CVE-2021-4275 | Med | 0.00 | 4.3 | 0.00 | Dec 21, 2022 | A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is… | ||
| CVE-2021-4268 | Med | 0.00 | 4.3 | 0.00 | Dec 21, 2022 | A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this… | ||
| CVE-2022-4604 | Med | 0.00 | 4.3 | 0.00 | Dec 18, 2022 | A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function register_endpoints of the file english-wp-admin.php. The manipulation leads to cross-site request forgery. The attack can be launched… | ||
| CVE-2022-4564 | Med | 0.00 | 4.3 | 0.00 | Dec 16, 2022 | A vulnerability classified as problematic has been found in University of Central Florida Materia up to 9.0.0. This affects the function before of the file fuel/app/classes/controller/api.php of the component API Controller. The manipulation leads to cross-site request forgery.… | ||
| CVE-2022-4397 | Med | 0.00 | 4.3 | 0.00 | Dec 10, 2022 | A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-site request forgery. It is possible to… | ||
| CVE-2022-23475 | Hig | 0.00 | 8.8 | 0.00 | Dec 6, 2022 | daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped… | ||
| CVE-2022-45149 | Med | 0.00 | 5.4 | 0.00 | Nov 23, 2022 | A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the… | ||
| CVE-2022-43418 | Med | 0.00 | 4.3 | 0.00 | Oct 19, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||
| CVE-2022-2986 | Hig | 0.00 | 8.8 | 0.00 | Oct 6, 2022 | Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. | ||
| CVE-2022-39268 | Hig | 0.00 | 8.1 | 0.00 | Sep 30, 2022 | ### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did not intend. This may cause actions to be performed on the website that can include inadvertent client or server data leakage, change of session state, or… | ||
| CVE-2022-41227 | Hig | 0.00 | 8.8 | 0.00 | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials. | ||
| CVE-2022-34780 | Med | 0.00 | 6.5 | 0.00 | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in… |
- risk 0.00cvss 5.0epss 0.00
icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is…
- risk 0.00cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.
- risk 0.00cvss 6.5epss 0.00
Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to…
- risk 0.00cvss 4.8epss 0.00
user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request…
- risk 0.00cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
- risk 0.00cvss 5.3epss 0.00
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they click on a malicious deep link on a Windows computer. (e.g. in…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading…
- risk 0.00cvss 4.3epss 0.00
A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is…
- risk 0.00cvss 4.3epss 0.00
A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this…
- risk 0.00cvss 4.3epss 0.00
A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerability is the function register_endpoints of the file english-wp-admin.php. The manipulation leads to cross-site request forgery. The attack can be launched…
- risk 0.00cvss 4.3epss 0.00
A vulnerability classified as problematic has been found in University of Central Florida Materia up to 9.0.0. This affects the function before of the file fuel/app/classes/controller/api.php of the component API Controller. The manipulation leads to cross-site request forgery.…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-site request forgery. It is possible to…
- risk 0.00cvss 8.8epss 0.00
daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped…
- risk 0.00cvss 5.4epss 0.00
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the…
- risk 0.00cvss 4.3epss 0.00
A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- risk 0.00cvss 8.8epss 0.00
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
- risk 0.00cvss 8.1epss 0.00
### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did not intend. This may cause actions to be performed on the website that can include inadvertent client or server data leakage, change of session state, or…
- risk 0.00cvss 8.8epss 0.00
A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.
- risk 0.00cvss 6.5epss 0.00
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…