CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 51 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-32424 | Hig | 0.57 | 8.8 | 0.00 | Jun 17, 2021 | In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized changes to an affected router via a specially crafted web page. If an authenticated user were to interact with a malicious web page it could allow for a complete… | ||
| CVE-2021-31659 | Hig | 0.57 | 8.8 | 0.01 | Jun 10, 2021 | TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator… | ||
| CVE-2020-26516 | Hig | 0.57 | 8.8 | 0.01 | Jun 8, 2021 | A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the… | ||
| CVE-2020-18265 | Hig | 0.57 | 8.8 | 0.01 | Jun 7, 2021 | Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member". | ||
| CVE-2020-18264 | Hig | 0.57 | 8.8 | 0.01 | Jun 7, 2021 | Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member". | ||
| CVE-2020-26641 | Hig | 0.57 | 8.8 | 0.01 | May 28, 2021 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts. | ||
| CVE-2019-14836 | Hig | 0.57 | 8.8 | 0.01 | May 26, 2021 | A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks. | ||
| CVE-2021-21549 | Hig | 0.57 | 8.8 | 0.00 | May 21, 2021 | Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to… | ||
| CVE-2020-18198 | Hig | 0.57 | 8.8 | 0.01 | May 17, 2021 | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images." | ||
| CVE-2020-18195 | Hig | 0.57 | 8.8 | 0.01 | May 17, 2021 | Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page." | ||
| CVE-2021-32402 | Hig | 0.57 | 8.8 | 0.01 | May 17, 2021 | Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules. | ||
| CVE-2021-32073 | Hig | 0.57 | 8.8 | 0.01 | May 15, 2021 | DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution. | ||
| CVE-2020-18964 | Hig | 0.57 | 8.8 | 0.01 | May 11, 2021 | Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges. | ||
| CVE-2020-19199 | Hig | 0.57 | 8.8 | 0.01 | May 10, 2021 | A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code. | ||
| CVE-2021-32096 | Hig | 0.57 | 8.8 | 0.01 | May 7, 2021 | The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter. | ||
| CVE-2021-24179 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2021 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it… | ||
| CVE-2021-24178 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2021 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored… | ||
| CVE-2020-23127 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2021 | Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user. | ||
| CVE-2020-36334 | Hig | 0.57 | 8.8 | 0.01 | May 5, 2021 | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database. | ||
| CVE-2021-29238 | Hig | 0.57 | 8.8 | 0.01 | May 3, 2021 | CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF). |
- risk 0.57cvss 8.8epss 0.00
In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized changes to an affected router via a specially crafted web page. If an authenticated user were to interact with a malicious web page it could allow for a complete…
- risk 0.57cvss 8.8epss 0.01
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator…
- risk 0.57cvss 8.8epss 0.01
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the…
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member".
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".
- risk 0.57cvss 8.8epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.
- risk 0.57cvss 8.8epss 0.00
Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially exploit this vulnerability, leading to a privileged victim application user being tricked into sending state-changing requests to…
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."
- risk 0.57cvss 8.8epss 0.01
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules.
- risk 0.57cvss 8.8epss 0.01
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.
- risk 0.57cvss 8.8epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code (for an eval call) via the CONSOLE_COMMAND_STRING parameter.
- risk 0.57cvss 8.8epss 0.01
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it…
- risk 0.57cvss 8.8epss 0.01
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored…
- risk 0.57cvss 8.8epss 0.01
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
- risk 0.57cvss 8.8epss 0.01
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
- risk 0.57cvss 8.8epss 0.01
CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).