VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 435 of 479
  • CVE-2022-34134HigJun 28, 2022
    risk 0.00cvss 8.8epss 0.00

    Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.

  • CVE-2022-29450MedJun 15, 2022
    risk 0.00cvss 5.4epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.

  • CVE-2021-41245MedApr 5, 2022
    risk 0.00cvss 6.5epss 0.01

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by…

  • CVE-2021-46426MedMar 25, 2022
    risk 0.00cvss 6.1epss 0.01

    phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

  • CVE-2022-0515MedMar 21, 2022
    risk 0.00cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.

  • CVE-2021-46252MedFeb 15, 2022
    risk 0.00cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses.

  • CVE-2022-21703MedFeb 8, 2022
    risk 0.00cvss 6.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users…

  • CVE-2021-45326HigFeb 8, 2022
    risk 0.00cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.

  • CVE-2022-0238MedJan 16, 2022
    risk 0.00cvss 4.3epss 0.01

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2022-0197HigJan 13, 2022
    risk 0.00cvss 8.8epss 0.01

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2022-0196HigJan 13, 2022
    risk 0.00cvss 8.8epss 0.01

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-41260HigDec 16, 2021
    risk 0.00cvss 8.2epss 0.00

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible. There are no known…

  • CVE-2021-43777MedNov 24, 2021
    risk 0.00cvss 6.8epss 0.00

    Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a…

  • CVE-2021-25965HigNov 16, 2021
    risk 0.00cvss 8.8epss 0.01

    In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the…

  • CVE-2021-24884CriOct 25, 2021
    risk 0.00cvss 9.6epss 0.03

    The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…

  • CVE-2021-41083HigSep 20, 2021
    risk 0.00cvss 8.0epss 0.00

    Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, SMS, etc, that - when visited, allows them control of the list control panel as if the bad actor was logged in themselves. This…

  • CVE-2021-38721MedSep 9, 2021
    risk 0.00cvss 6.5epss 0.01

    FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability

  • CVE-2021-32774MedJul 20, 2021
    risk 0.00cvss 6.1epss 0.00

    DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, DataDump had no protection against CSRF attacks so requests to generate or delete dumps could be forged. The vulnerability was patched in commit…

  • CVE-2021-21675MedJun 30, 2021
    risk 0.00cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.

  • CVE-2021-21665HigJun 10, 2021
    risk 0.00cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials…