CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,651)
page 44 of 483| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32159 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. | ||
| CVE-2021-32156 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. | ||
| CVE-2020-4668 | Hig | 0.57 | 8.8 | 0.00 | Apr 8, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM… | ||
| CVE-2021-44312 | Hig | 0.57 | 8.8 | 0.00 | Mar 30, 2022 | An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page. | ||
| CVE-2022-27432 | Hig | 0.57 | 8.8 | 0.01 | Mar 30, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover. | ||
| CVE-2022-28150 | Hig | 0.57 | 8.8 | 0.01 | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job. | ||
| CVE-2022-0770 | Hig | 0.57 | 8.8 | 0.01 | Mar 28, 2022 | The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker… | ||
| CVE-2022-0499 | Hig | 0.57 | 8.8 | 0.01 | Mar 28, 2022 | The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones. | ||
| CVE-2022-25523 | Hig | 0.57 | 8.8 | 0.01 | Mar 25, 2022 | TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request. | ||
| CVE-2022-25268 | Hig | 0.57 | 8.8 | 0.00 | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems. | ||
| CVE-2021-43738 | Hig | 0.57 | 8.8 | 0.00 | Mar 23, 2022 | An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account. | ||
| CVE-2021-40662 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2022 | A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL. | ||
| CVE-2022-23349 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF). | ||
| CVE-2022-24235 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2022 | A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. | ||
| CVE-2022-22346 | Hig | 0.57 | 8.8 | 0.00 | Mar 14, 2022 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220048. | ||
| CVE-2021-45886 | Hig | 0.57 | 8.8 | 0.01 | Mar 13, 2022 | An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of… | ||
| CVE-2020-18326 | Hig | 0.57 | 8.8 | 0.02 | Mar 4, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user. | ||
| CVE-2021-24803 | Hig | 0.57 | 8.8 | 0.01 | Feb 28, 2022 | The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create… | ||
| CVE-2021-24704 | Hig | 0.57 | 8.8 | 0.01 | Feb 28, 2022 | In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF… | ||
| CVE-2022-24342 | Hig | 0.57 | 8.8 | 0.03 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. |
- risk 0.57cvss 8.8epss 0.02
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- risk 0.57cvss 8.8epss 0.02
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- risk 0.57cvss 8.8epss 0.00
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job.
- risk 0.57cvss 8.8epss 0.01
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker…
- risk 0.57cvss 8.8epss 0.01
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.
- risk 0.57cvss 8.8epss 0.01
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
- risk 0.57cvss 8.8epss 0.00
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
- risk 0.57cvss 8.8epss 0.01
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
- risk 0.57cvss 8.8epss 0.00
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220048.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of…
- risk 0.57cvss 8.8epss 0.02
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
- risk 0.57cvss 8.8epss 0.01
The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create…
- risk 0.57cvss 8.8epss 0.01
In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF…
- risk 0.57cvss 8.8epss 0.03
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.