VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,651)

page 45 of 483
  • CVE-2022-24947HigFeb 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.

  • CVE-2022-0134HigFeb 21, 2022
    risk 0.57cvss 8.8epss 0.01

    The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack

  • CVE-2022-25242HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).

  • CVE-2022-25212HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.

  • CVE-2022-25207HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.

  • CVE-2022-25205HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.

  • CVE-2022-25200HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-25198HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2022-23384HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add

  • CVE-2021-46366HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

  • CVE-2022-22808HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.01

    A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV…

  • CVE-2021-22954HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.

  • CVE-2021-24879HigFeb 7, 2022
    risk 0.57cvss 8.8epss 0.01

    The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an…

  • CVE-2020-7534HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.00

    A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions),…

  • CVE-2021-45268HigFeb 3, 2022
    risk 0.57cvss 8.8epss 0.02

    A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack…

  • CVE-2021-39044HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.

  • CVE-2021-24763HigFeb 1, 2022
    risk 0.57cvss 8.8epss 0.01

    The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could…

  • CVE-2022-23888HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.01

    YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.

  • CVE-2021-22725HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server. Affected Products:…

  • CVE-2021-22724HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server. Affected Products:…