VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 61 of 482
  • CVE-2020-9341HigFeb 22, 2020
    risk 0.57cvss 8.8epss 0.01

    CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.

  • CVE-2020-3114HigFeb 19, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2020-9270HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.

  • CVE-2020-6844HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.

  • CVE-2013-4227HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a…

  • CVE-2020-5530HigFeb 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2013-2109HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.02

    WordPress plugin wp-cleanfix has Remote Code Execution

  • CVE-2019-19659HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.00

    A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html.

  • CVE-2019-20059HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.01

    payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the…

  • CVE-2011-1085HigFeb 7, 2020
    risk 0.57cvss 8.8epss 0.00

    CSRF vulnerability in Smoothwall Express 3.

  • CVE-2012-6297HigFeb 6, 2020
    risk 0.57cvss 8.8epss 0.02

    Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.

  • CVE-2011-0525HigFeb 5, 2020
    risk 0.57cvss 8.8epss 0.01

    Batavi before 1.0 has CSRF.

  • CVE-2019-4613HigFeb 5, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.

  • CVE-2020-8420HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

  • CVE-2020-8419HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

  • CVE-2013-3093HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-N56U devices allow CSRF.

  • CVE-2015-5483HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or…

  • CVE-2019-16513HigJan 23, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.

  • CVE-2011-3612HigJan 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

  • CVE-2011-3582HigJan 22, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.