CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 57 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-5904 | Hig | 0.57 | 8.8 | 0.01 | Jul 1, 2020 | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page. | ||
| CVE-2020-5900 | Hig | 0.57 | 8.8 | 0.00 | Jul 1, 2020 | In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface. | ||
| CVE-2020-15014 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2020 | pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF. | ||
| CVE-2020-13155 | Hig | 0.57 | 8.8 | 0.01 | Jun 23, 2020 | clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI. | ||
| CVE-2020-14203 | Hig | 0.57 | 8.8 | 0.00 | Jun 22, 2020 | WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with… | ||
| CVE-2019-20865 | Hig | 0.57 | 8.8 | 0.00 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF. | ||
| CVE-2019-20841 | Hig | 0.57 | 8.8 | 0.00 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks. | ||
| CVE-2020-14432 | Hig | 0.57 | 8.8 | 0.00 | Jun 18, 2020 | Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before… | ||
| CVE-2020-7503 | Hig | 0.57 | 8.8 | 0.01 | Jun 16, 2020 | A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted. | ||
| CVE-2019-19109 | Hig | 0.57 | 8.8 | 0.01 | Jun 15, 2020 | The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. | ||
| CVE-2020-9042 | Hig | 0.57 | 8.8 | 0.01 | Jun 8, 2020 | In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request. | ||
| CVE-2020-13786 | Hig | 0.57 | 8.8 | 0.01 | Jun 3, 2020 | D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF. | ||
| CVE-2020-13760 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2020 | In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. | ||
| CVE-2014-8942 | Hig | 0.57 | 8.8 | 0.00 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows CSRF. | ||
| CVE-2020-4018 | Hig | 0.57 | 8.8 | 0.01 | Jun 1, 2020 | The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability. | ||
| CVE-2020-13643 | Hig | 0.57 | 8.8 | 0.01 | May 28, 2020 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for… | ||
| CVE-2020-13642 | Hig | 0.57 | 8.8 | 0.01 | May 28, 2020 | An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for… | ||
| CVE-2020-13641 | Hig | 0.57 | 8.8 | 0.01 | May 28, 2020 | An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with… | ||
| CVE-2020-8168 | Hig | 0.57 | 8.8 | 0.01 | May 26, 2020 | We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against… | ||
| CVE-2020-13458 | Hig | 0.57 | 8.8 | 0.00 | May 25, 2020 | An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action. |
- risk 0.57cvss 8.8epss 0.01
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, exists in an undisclosed page.
- risk 0.57cvss 8.8epss 0.00
In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface.
- risk 0.57cvss 8.8epss 0.01
pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
- risk 0.57cvss 8.8epss 0.01
clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.
- risk 0.57cvss 8.8epss 0.00
WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.
- risk 0.57cvss 8.8epss 0.00
Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before…
- risk 0.57cvss 8.8epss 0.01
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.
- risk 0.57cvss 8.8epss 0.01
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
- risk 0.57cvss 8.8epss 0.01
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request.
- risk 0.57cvss 8.8epss 0.01
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
- risk 0.57cvss 8.8epss 0.01
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
- risk 0.57cvss 8.8epss 0.00
Lexiglot through 2014-11-20 allows CSRF.
- risk 0.57cvss 8.8epss 0.01
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with…
- risk 0.57cvss 8.8epss 0.01
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.