VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 57 of 482
  • CVE-2020-5904HigJul 1, 2020
    risk 0.57cvss 8.8epss 0.01

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page.

  • CVE-2020-5900HigJul 1, 2020
    risk 0.57cvss 8.8epss 0.00

    In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface.

  • CVE-2020-15014HigJun 24, 2020
    risk 0.57cvss 8.8epss 0.01

    pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.

  • CVE-2020-13155HigJun 23, 2020
    risk 0.57cvss 8.8epss 0.01

    clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.

  • CVE-2020-14203HigJun 22, 2020
    risk 0.57cvss 8.8epss 0.00

    WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with…

  • CVE-2019-20865HigJun 19, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.

  • CVE-2019-20841HigJun 19, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.

  • CVE-2020-14432HigJun 18, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before…

  • CVE-2020-7503HigJun 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.

  • CVE-2019-19109HigJun 15, 2020
    risk 0.57cvss 8.8epss 0.01

    The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.

  • CVE-2020-9042HigJun 8, 2020
    risk 0.57cvss 8.8epss 0.01

    In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request.

  • CVE-2020-13786HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

  • CVE-2020-13760HigJun 2, 2020
    risk 0.57cvss 8.8epss 0.01

    In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.

  • CVE-2014-8942HigJun 1, 2020
    risk 0.57cvss 8.8epss 0.00

    Lexiglot through 2014-11-20 allows CSRF.

  • CVE-2020-4018HigJun 1, 2020
    risk 0.57cvss 8.8epss 0.01

    The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.

  • CVE-2020-13643HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for…

  • CVE-2020-13642HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for…

  • CVE-2020-13641HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with…

  • CVE-2020-8168HigMay 26, 2020
    risk 0.57cvss 8.8epss 0.01

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against…

  • CVE-2020-13458HigMay 25, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.