VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 49 of 482
  • CVE-2021-24491HigSep 13, 2021
    risk 0.57cvss 8.8epss 0.01

    The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload and delete files. As a result, attackers could make a logged in administrator delete and upload arbitrary files via a CSRF attack

  • CVE-2020-19280HigSep 9, 2021
    risk 0.57cvss 8.8epss 0.01

    Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.

  • CVE-2020-19263HigSep 9, 2021
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/ApiAdminUser/itemEdit.

  • CVE-2021-38705HigSep 7, 2021
    risk 0.57cvss 8.8epss 0.01

    ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to…

  • CVE-2020-19047HigAug 31, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.

  • CVE-2021-40174HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.

  • CVE-2021-40173HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

  • CVE-2021-40172HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.

  • CVE-2020-18917HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.01

    The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.

  • CVE-2021-24565HigAug 23, 2021
    risk 0.57cvss 8.8epss 0.01

    The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading…

  • CVE-2021-24555HigAug 23, 2021
    risk 0.57cvss 8.8epss 0.01

    The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is…

  • CVE-2021-28490HigAug 19, 2021
    risk 0.57cvss 8.8epss 0.01

    In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.

  • CVE-2020-20642HigAug 19, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.

  • CVE-2021-34645HigAug 19, 2021
    risk 0.57cvss 8.8epss 0.01

    The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to…

  • CVE-2020-19669HigAug 18, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.

  • CVE-2020-18460HigAug 12, 2021
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content.

  • CVE-2021-37366HigAug 10, 2021
    risk 0.57cvss 8.8epss 0.01

    CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker can trick the administrator into clicking a link that cancels the filtering for all standard users.

  • CVE-2020-18694HigAug 6, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/admin/profile/save_profile".

  • CVE-2021-37381HigAug 6, 2021
    risk 0.57cvss 8.8epss 0.01

    Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any student's photo information can be accessed through /gmis/(S([1]))/student/grgl/PotoImageShow/?bh=[2]. Among them, the code in…

  • CVE-2021-34634HigAug 5, 2021
    risk 0.57cvss 8.8epss 0.01

    The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.