VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 51 of 482
  • CVE-2021-32424HigJun 17, 2021
    risk 0.57cvss 8.8epss 0.00

    In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized changes to an affected router via a specially crafted web page. If an authenticated user were to interact with a malicious web page it could allow for a complete…

  • CVE-2021-31659HigJun 10, 2021
    risk 0.57cvss 8.8epss 0.01

    TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator…

  • CVE-2020-26516HigJun 8, 2021
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the…

  • CVE-2020-18265HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member".

  • CVE-2020-18264HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".

  • CVE-2020-26641HigMay 28, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.

  • CVE-2019-14836HigMay 26, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

  • CVE-2021-21549HigMay 21, 2021
    risk 0.57cvss 8.8epss 0.00

    Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to…

  • CVE-2020-18198HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."

  • CVE-2020-18195HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."

  • CVE-2021-32402HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules.

  • CVE-2021-32073HigMay 15, 2021
    risk 0.57cvss 8.8epss 0.01

    DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.

  • CVE-2020-18964HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.

  • CVE-2020-19199HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.

  • CVE-2021-32096HigMay 7, 2021
    risk 0.57cvss 8.8epss 0.01

    The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.

  • CVE-2021-24179HigMay 6, 2021
    risk 0.57cvss 8.8epss 0.01

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it…

  • CVE-2021-24178HigMay 6, 2021
    risk 0.57cvss 8.8epss 0.01

    The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored…

  • CVE-2020-23127HigMay 6, 2021
    risk 0.57cvss 8.8epss 0.01

    Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

  • CVE-2020-36334HigMay 5, 2021
    risk 0.57cvss 8.8epss 0.01

    themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.

  • CVE-2021-29238HigMay 3, 2021
    risk 0.57cvss 8.8epss 0.01

    CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).