VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 53 of 482
  • CVE-2021-26960HigMar 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an unauthenticated remote attacker to conduct a…

  • CVE-2021-27927HigMar 3, 2021
    risk 0.57cvss 8.8epss 0.02

    In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls diableSIDValidation inside the…

  • CVE-2020-27997HigFeb 19, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).

  • CVE-2021-20073HigFeb 16, 2021
    risk 0.57cvss 8.8epss 0.00

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.

  • CVE-2021-20403HigFeb 11, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

  • CVE-2020-35942HigFeb 9, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a…

  • CVE-2020-13460HigFeb 9, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.

  • CVE-2021-20652HigFeb 5, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2021-25765HigFeb 3, 2021
    risk 0.57cvss 8.8epss 0.01

    In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.

  • CVE-2020-24271HigFeb 1, 2021
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.

  • CVE-2020-29004HigJan 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.

  • CVE-2020-13569HigJan 28, 2021
    risk 0.57cvss 8.8epss 0.03

    A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the…

  • CVE-2021-20621HigJan 28, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2020-35239HigJan 26, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP…

  • CVE-2020-12511HigJan 22, 2021
    risk 0.57cvss 8.8epss 0.01

    Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

  • CVE-2021-1257HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness…

  • CVE-2020-6776HigJan 14, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (Cross-Site…

  • CVE-2020-4942HigJan 4, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191942.

  • CVE-2020-4917HigJan 4, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191391.

  • CVE-2021-21495HigJan 4, 2021
    risk 0.57cvss 8.8epss 0.01

    MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.