VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 55 of 482
  • CVE-2020-28649HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.01

    The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.

  • CVE-2019-7357HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.

  • CVE-2020-27016HigNov 9, 2020
    risk 0.57cvss 8.8epss 0.02

    Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could allow an attacker to modify policy rules by tricking an authenticated administrator into accessing an attacker-controlled web…

  • CVE-2020-27692HigNov 4, 2020
    risk 0.57cvss 8.8epss 0.01

    The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. Attackers can, for example, use this to update the TR-069 configuration server settings (responsible for managing devices remotely).…

  • CVE-2020-11485HigOct 29, 2020
    risk 0.57cvss 8.8epss 0.01

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC firmware in which the web application does not sufficiently verify whether a well-formed, valid, consistent request was…

  • CVE-2020-16256HigOct 28, 2020
    risk 0.57cvss 8.8epss 0.01

    The API on Winston 1.5.4 devices is vulnerable to CSRF.

  • CVE-2020-27975HigOct 28, 2020
    risk 0.57cvss 8.8epss 0.01

    osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

  • CVE-2020-18129HigOct 22, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.

  • CVE-2020-24033HigOct 22, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating…

  • CVE-2020-3456HigOct 21, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device. The vulnerability is due to insufficient CSRF…

  • CVE-2020-12502HigOct 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3…

  • CVE-2020-5642HigOct 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2020-26522HigOct 9, 2020
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.

  • CVE-2020-26802HigOct 8, 2020
    risk 0.57cvss 8.8epss 0.01

    forma.lms 2.3.0.2 is affected by Cross Site Request Forgery (CSRF) in formalms/appCore/index.php?r=lms/profile/show&ap=saveinfo via a GET request to change the admin email address in order to accomplish an account takeover.

  • CVE-2020-23837HigSep 25, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.

  • CVE-2020-12282HigSep 24, 2020
    risk 0.57cvss 8.8epss 0.01

    iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be combined with reflected XSS.)

  • CVE-2020-2280HigSep 23, 2020
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code.

  • CVE-2020-3135HigSep 23, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. The vulnerability is due to insufficient CSRF…

  • CVE-2019-16009HigSep 23, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an…

  • CVE-2020-14025HigSep 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password.