CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 54 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-35950 | Cri | 0.57 | 9.8 | 0.01 | Jan 1, 2021 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint). | ||
| CVE-2020-35944 | Hig | 0.57 | 8.8 | 0.01 | Jan 1, 2021 | An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS. | ||
| CVE-2018-16795 | Hig | 0.57 | 8.8 | 0.01 | Dec 31, 2020 | OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file. | ||
| CVE-2020-35773 | Hig | 0.57 | 8.8 | 0.01 | Dec 29, 2020 | The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF. | ||
| CVE-2020-26766 | Hig | 0.57 | 8.8 | 0.01 | Dec 26, 2020 | A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1. | ||
| CVE-2020-35269 | Hig | 0.57 | 8.8 | 0.02 | Dec 23, 2020 | Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers. | ||
| CVE-2020-35626 | Hig | 0.57 | 8.8 | 0.01 | Dec 21, 2020 | An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php. | ||
| CVE-2020-7201 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2020 | A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF). | ||
| CVE-2020-8461 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2020 | A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token. | ||
| CVE-2020-25095 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2020 | LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user visits a malicious site in the same browser session, that site can perform a CSRF attack to create a WebSocket from the victim… | ||
| CVE-2020-28931 | Hig | 0.57 | 8.8 | 0.01 | Dec 16, 2020 | Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website. | ||
| CVE-2020-25622 | Hig | 0.57 | 8.8 | 0.01 | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. | ||
| CVE-2019-19289 | Hig | 0.57 | 8.8 | 0.00 | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. | ||
| CVE-2020-8282 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2020 | A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution. | ||
| CVE-2020-28858 | Hig | 0.57 | 8.8 | 0.01 | Dec 14, 2020 | OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions. | ||
| CVE-2020-29254 | Hig | 0.57 | 8.8 | 0.01 | Dec 11, 2020 | TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF… | ||
| CVE-2020-35135 | Hig | 0.57 | 8.8 | 0.01 | Dec 11, 2020 | The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. | ||
| CVE-2020-29458 | Hig | 0.57 | 8.8 | 0.01 | Dec 2, 2020 | Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem. | ||
| CVE-2020-26936 | Hig | 0.57 | 8.8 | 0.00 | Nov 26, 2020 | Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack. | ||
| CVE-2020-13620 | Hig | 0.57 | 8.8 | 0.01 | Nov 24, 2020 | Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration. |
- risk 0.57cvss 9.8epss 0.01
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
- risk 0.57cvss 8.8epss 0.01
OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.
- risk 0.57cvss 8.8epss 0.01
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
- risk 0.57cvss 8.8epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.
- risk 0.57cvss 8.8epss 0.02
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.
- risk 0.57cvss 8.8epss 0.01
A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.01
A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.
- risk 0.57cvss 8.8epss 0.01
LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user visits a malicious site in the same browser session, that site can perform a CSRF attack to create a WebSocket from the victim…
- risk 0.57cvss 8.8epss 0.01
Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link.
- risk 0.57cvss 8.8epss 0.01
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.
- risk 0.57cvss 8.8epss 0.01
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.
- risk 0.57cvss 8.8epss 0.01
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF…
- risk 0.57cvss 8.8epss 0.01
The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.
- risk 0.57cvss 8.8epss 0.01
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.
- risk 0.57cvss 8.8epss 0.00
Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.
- risk 0.57cvss 8.8epss 0.01
Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.