VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 54 of 482
  • CVE-2020-35950CriJan 1, 2021
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

  • CVE-2020-35944HigJan 1, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.

  • CVE-2018-16795HigDec 31, 2020
    risk 0.57cvss 8.8epss 0.01

    OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.

  • CVE-2020-35773HigDec 29, 2020
    risk 0.57cvss 8.8epss 0.01

    The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.

  • CVE-2020-26766HigDec 26, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.

  • CVE-2020-35269HigDec 23, 2020
    risk 0.57cvss 8.8epss 0.02

    Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.

  • CVE-2020-35626HigDec 21, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.

  • CVE-2020-7201HigDec 18, 2020
    risk 0.57cvss 8.8epss 0.01

    A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).

  • CVE-2020-8461HigDec 17, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.

  • CVE-2020-25095HigDec 17, 2020
    risk 0.57cvss 8.8epss 0.01

    LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user visits a malicious site in the same browser session, that site can perform a CSRF attack to create a WebSocket from the victim…

  • CVE-2020-28931HigDec 16, 2020
    risk 0.57cvss 8.8epss 0.01

    Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.

  • CVE-2020-25622HigDec 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

  • CVE-2019-19289HigDec 14, 2020
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link.

  • CVE-2020-8282HigDec 14, 2020
    risk 0.57cvss 8.8epss 0.01

    A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.

  • CVE-2020-28858HigDec 14, 2020
    risk 0.57cvss 8.8epss 0.01

    OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

  • CVE-2020-29254HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.01

    TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2020-35135HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.01

    The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.

  • CVE-2020-29458HigDec 2, 2020
    risk 0.57cvss 8.8epss 0.01

    Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

  • CVE-2020-26936HigNov 26, 2020
    risk 0.57cvss 8.8epss 0.00

    Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.

  • CVE-2020-13620HigNov 24, 2020
    risk 0.57cvss 8.8epss 0.01

    Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.