VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 56 of 482
  • CVE-2020-24373HigSep 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.

  • CVE-2020-2268HigSep 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any arbitrary files on the Jenkins controller.

  • CVE-2020-23451HigSep 15, 2020
    risk 0.57cvss 8.8epss 0.01

    Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

  • CVE-2020-10229HigSep 14, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts.

  • CVE-2020-23824HigSep 11, 2020
    risk 0.57cvss 8.8epss 0.01

    ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will…

  • CVE-2020-25252HigSep 11, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default credentials (the wstinol…

  • CVE-2020-25070HigSep 1, 2020
    risk 0.57cvss 8.8epss 0.00

    USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.

  • CVE-2020-16208HigSep 1, 2020
    risk 0.57cvss 8.8epss 0.01

    The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions).

  • CVE-2020-23836HigSep 1, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.

  • CVE-2020-5922HigAug 26, 2020
    risk 0.57cvss 8.8epss 0.01

    In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Site Request Forgery protections for users which make use of Basic Authentication in a web browser.

  • CVE-2020-14043HigAug 24, 2020
    risk 0.57cvss 8.8epss 0.02

    ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in…

  • CVE-2020-19889HigAug 24, 2020
    risk 0.57cvss 8.8epss 0.01

    DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.

  • CVE-2020-5615HigAug 4, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2020-5770HigAug 3, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

  • CVE-2020-10984HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.01

    Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.

  • CVE-2020-5611HigJul 27, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2020-11438HigJul 15, 2020
    risk 0.57cvss 8.8epss 0.01

    LibreHealth EMR v2.0.0 is affected by systemic CSRF.

  • CVE-2019-12784HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them…

  • CVE-2020-6289HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.00

    SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site.

  • CVE-2020-15711HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.00

    In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.