VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 58 of 482
  • CVE-2020-13412HigMay 22, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.

  • CVE-2019-20804HigMay 21, 2020
    risk 0.57cvss 8.8epss 0.01

    Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.

  • CVE-2020-12257HigMay 18, 2020
    risk 0.57cvss 8.8epss 0.01

    rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker can leverage this vulnerability by creating a form (add a user, delete a user, or edit a user).

  • CVE-2020-5576HigMay 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier (Movable Type Advanced 7), Movable Type for AWS 7 r.4606 (7.2.1) and earlier (Movable Type for…

  • CVE-2020-12427HigMay 13, 2020
    risk 0.57cvss 8.8epss 0.00

    The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.

  • CVE-2020-8830HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

  • CVE-2020-8829HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.

  • CVE-2019-19517HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.

  • CVE-2019-4750HigApr 24, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 173310.

  • CVE-2017-18703HigApr 24, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, EX6100v2 before 1.0.1.60, EX6150v2 before 1.0.1.60, JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.16,…

  • CVE-2017-18708HigApr 24, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects R8300 before 1.0.2.94 and R8500 before 1.0.2.94.

  • CVE-2018-21160HigApr 23, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

  • CVE-2018-21102HigApr 23, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

  • CVE-2017-18749HigApr 23, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, R6050 before 1.0.1.10, R6100 before 1.0.1.16, R6220 before 1.1.0.50, R7500 before 1.0.0.112, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36,…

  • CVE-2017-18742HigApr 23, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6250 before 1.0.4.12, R6300v2 before 1.0.4.8, R6700 before 1.0.1.16, R6900 before 1.0.1.16, R7300DST before 1.0.0.54, R7900 before 1.0.1.12, R8000 before 1.0.3.32, and…

  • CVE-2020-12076HigApr 23, 2020
    risk 0.57cvss 8.8epss 0.01

    The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.

  • CVE-2020-10892HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-10890HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2017-18755HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000P before 1.0.0.86, R6900P before 1.0.0.56, R7300 before 1.0.0.54, R8300 before 1.0.2.106, R8500 before 1.0.2.106,…

  • CVE-2017-18768HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by CSRF. This affects EX6100 before 1.0.2.16_1.1.130, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.54, EX6200v2 before 1.0.1.50, EX6400 before 1.0.1.60, EX7300 before 1.0.1.60, and WN3000RPv3 before 1.0.2.44.