CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 56 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24373 | Hig | 0.57 | 8.8 | 0.01 | Sep 16, 2020 | A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3. | ||
| CVE-2020-2268 | Hig | 0.57 | 8.8 | 0.01 | Sep 16, 2020 | A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any arbitrary files on the Jenkins controller. | ||
| CVE-2020-23451 | Hig | 0.57 | 8.8 | 0.01 | Sep 15, 2020 | Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function. | ||
| CVE-2020-10229 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2020 | A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts. | ||
| CVE-2020-23824 | Hig | 0.57 | 8.8 | 0.01 | Sep 11, 2020 | ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will… | ||
| CVE-2020-25252 | Hig | 0.57 | 8.8 | 0.01 | Sep 11, 2020 | An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default credentials (the wstinol… | ||
| CVE-2020-25070 | Hig | 0.57 | 8.8 | 0.00 | Sep 1, 2020 | USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature. | ||
| CVE-2020-16208 | Hig | 0.57 | 8.8 | 0.01 | Sep 1, 2020 | The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions). | ||
| CVE-2020-23836 | Hig | 0.57 | 8.8 | 0.01 | Sep 1, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site. | ||
| CVE-2020-5922 | Hig | 0.57 | 8.8 | 0.01 | Aug 26, 2020 | In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Site Request Forgery protections for users which make use of Basic Authentication in a web browser. | ||
| CVE-2020-14043 | Hig | 0.57 | 8.8 | 0.02 | Aug 24, 2020 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in… | ||
| CVE-2020-19889 | Hig | 0.57 | 8.8 | 0.01 | Aug 24, 2020 | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. | ||
| CVE-2020-5615 | Hig | 0.57 | 8.8 | 0.01 | Aug 4, 2020 | Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2020-5770 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2020 | Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | ||
| CVE-2020-10984 | Hig | 0.57 | 8.8 | 0.01 | Jul 28, 2020 | Gambio GX before 4.0.1.0 allows admin/admin.php CSRF. | ||
| CVE-2020-5611 | Hig | 0.57 | 8.8 | 0.01 | Jul 27, 2020 | Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2020-11438 | Hig | 0.57 | 8.8 | 0.01 | Jul 15, 2020 | LibreHealth EMR v2.0.0 is affected by systemic CSRF. | ||
| CVE-2019-12784 | Hig | 0.57 | 8.8 | 0.01 | Jul 14, 2020 | An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them… | ||
| CVE-2020-6289 | Hig | 0.57 | 8.8 | 0.00 | Jul 14, 2020 | SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site. | ||
| CVE-2020-15711 | Hig | 0.57 | 8.8 | 0.00 | Jul 14, 2020 | In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. |
- risk 0.57cvss 8.8epss 0.01
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any arbitrary files on the Jenkins controller.
- risk 0.57cvss 8.8epss 0.01
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
- risk 0.57cvss 8.8epss 0.01
A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts.
- risk 0.57cvss 8.8epss 0.01
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default credentials (the wstinol…
- risk 0.57cvss 8.8epss 0.00
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
- risk 0.57cvss 8.8epss 0.01
The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions).
- risk 0.57cvss 8.8epss 0.01
A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.
- risk 0.57cvss 8.8epss 0.01
In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Site Request Forgery protections for users which make use of Basic Authentication in a web browser.
- risk 0.57cvss 8.8epss 0.02
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in…
- risk 0.57cvss 8.8epss 0.01
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
- risk 0.57cvss 8.8epss 0.01
Gambio GX before 4.0.1.0 allows admin/admin.php CSRF.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
LibreHealth EMR v2.0.0 is affected by systemic CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them…
- risk 0.57cvss 8.8epss 0.00
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site.
- risk 0.57cvss 8.8epss 0.00
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.