CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 435 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34134 | Hig | 0.00 | 8.8 | 0.00 | Jun 28, 2022 | Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php. | ||
| CVE-2022-29450 | Med | 0.00 | 5.4 | 0.00 | Jun 15, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress. | ||
| CVE-2021-41245 | Med | 0.00 | 6.5 | 0.01 | Apr 5, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by… | ||
| CVE-2021-46426 | Med | 0.00 | 6.1 | 0.01 | Mar 25, 2022 | phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality. | ||
| CVE-2022-0515 | Med | 0.00 | 4.3 | 0.00 | Mar 21, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | ||
| CVE-2021-46252 | Med | 0.00 | 6.5 | 0.00 | Feb 15, 2022 | A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses. | ||
| CVE-2022-21703 | Med | 0.00 | 6.3 | 0.02 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users… | ||
| CVE-2021-45326 | Hig | 0.00 | 8.8 | 0.01 | Feb 8, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests. | ||
| CVE-2022-0238 | Med | 0.00 | 4.3 | 0.01 | Jan 16, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2022-0197 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2022-0196 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-41260 | Hig | 0.00 | 8.2 | 0.00 | Dec 16, 2021 | Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible. There are no known… | ||
| CVE-2021-43777 | Med | 0.00 | 6.8 | 0.00 | Nov 24, 2021 | Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a… | ||
| CVE-2021-25965 | Hig | 0.00 | 8.8 | 0.01 | Nov 16, 2021 | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the… | ||
| CVE-2021-24884 | Cri | 0.00 | 9.6 | 0.03 | Oct 25, 2021 | The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick… | ||
| CVE-2021-41083 | Hig | 0.00 | 8.0 | 0.00 | Sep 20, 2021 | Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, SMS, etc, that - when visited, allows them control of the list control panel as if the bad actor was logged in themselves. This… | ||
| CVE-2021-38721 | Med | 0.00 | 6.5 | 0.01 | Sep 9, 2021 | FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability | ||
| CVE-2021-32774 | Med | 0.00 | 6.1 | 0.00 | Jul 20, 2021 | DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, DataDump had no protection against CSRF attacks so requests to generate or delete dumps could be forged. The vulnerability was patched in commit… | ||
| CVE-2021-21675 | Med | 0.00 | 6.5 | 0.01 | Jun 30, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests. | ||
| CVE-2021-21665 | Hig | 0.00 | 8.8 | 0.01 | Jun 10, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials… |
- risk 0.00cvss 8.8epss 0.00
Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.
- risk 0.00cvss 5.4epss 0.00
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
- risk 0.00cvss 6.5epss 0.01
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by…
- risk 0.00cvss 6.1epss 0.01
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
- risk 0.00cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
- risk 0.00cvss 6.5epss 0.00
A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses.
- risk 0.00cvss 6.3epss 0.02
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users…
- risk 0.00cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.
- risk 0.00cvss 4.3epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.2epss 0.00
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible. There are no known…
- risk 0.00cvss 6.8epss 0.00
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a…
- risk 0.00cvss 8.8epss 0.01
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the…
- risk 0.00cvss 9.6epss 0.03
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…
- risk 0.00cvss 8.0epss 0.00
Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, SMS, etc, that - when visited, allows them control of the list control panel as if the bad actor was logged in themselves. This…
- risk 0.00cvss 6.5epss 0.01
FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability
- risk 0.00cvss 6.1epss 0.00
DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, DataDump had no protection against CSRF attacks so requests to generate or delete dumps could be forged. The vulnerability was patched in commit…
- risk 0.00cvss 6.5epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.
- risk 0.00cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials…