VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 60 of 482
  • CVE-2020-10671HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.01

    The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.

  • CVE-2019-12769HigMar 18, 2020
    risk 0.57cvss 8.8epss 0.01

    SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.

  • CVE-2018-21037HigMar 17, 2020
    risk 0.57cvss 8.8epss 0.01

    Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.

  • CVE-2020-9346HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.

  • CVE-2020-6585HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    Nagios Log Server 2.1.3 has CSRF.

  • CVE-2020-10241HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

  • CVE-2020-10568HigMar 14, 2020
    risk 0.57cvss 8.8epss 0.02

    The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

  • CVE-2019-13395HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.00

    The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.

  • CVE-2020-10540HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.00

    Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.

  • CVE-2019-17653HigMar 12, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.

  • CVE-2020-10478HigMar 12, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.

  • CVE-2020-9454HigMar 6, 2020
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and…

  • CVE-2019-17642HigMar 5, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.

  • CVE-2020-10057HigMar 4, 2020
    risk 0.57cvss 8.8epss 0.01

    GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an…

  • CVE-2020-7988HigMar 4, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old…

  • CVE-2019-20487HigMar 2, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI.

  • CVE-2020-5402HigFeb 27, 2020
    risk 0.57cvss 8.8epss 0.00

    In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.

  • CVE-2015-5686HigFeb 27, 2020
    risk 0.57cvss 8.8epss 0.00

    Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

  • CVE-2020-9394HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.

  • CVE-2019-20480HigFeb 24, 2020
    risk 0.57cvss 8.8epss 0.00

    In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.