VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,651)

page 44 of 483
  • CVE-2021-32159HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

  • CVE-2021-32156HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

  • CVE-2020-4668HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM…

  • CVE-2021-44312HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.

  • CVE-2022-27432HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

  • CVE-2022-28150HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job.

  • CVE-2022-0770HigMar 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker…

  • CVE-2022-0499HigMar 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

  • CVE-2022-25523HigMar 25, 2022
    risk 0.57cvss 8.8epss 0.01

    TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

  • CVE-2022-25268HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.00

    Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.

  • CVE-2021-43738HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.

  • CVE-2021-40662HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.

  • CVE-2022-23349HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

  • CVE-2022-24235HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.

  • CVE-2022-22346HigMar 14, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220048.

  • CVE-2021-45886HigMar 13, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (such as operator) can be used to confirm actions of…

  • CVE-2020-18326HigMar 4, 2022
    risk 0.57cvss 8.8epss 0.02

    Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

  • CVE-2021-24803HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create…

  • CVE-2021-24704HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.01

    In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF…

  • CVE-2022-24342HigFeb 25, 2022
    risk 0.57cvss 8.8epss 0.03

    In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.