CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 61 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-9341 | Hig | 0.57 | 8.8 | 0.01 | Feb 22, 2020 | CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI. | ||
| CVE-2020-3114 | Hig | 0.57 | 8.8 | 0.01 | Feb 19, 2020 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF… | ||
| CVE-2020-9270 | Hig | 0.57 | 8.8 | 0.01 | Feb 18, 2020 | ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php. | ||
| CVE-2020-6844 | Hig | 0.57 | 8.8 | 0.01 | Feb 18, 2020 | In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts. | ||
| CVE-2013-4227 | Hig | 0.57 | 8.8 | 0.01 | Feb 18, 2020 | Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a… | ||
| CVE-2020-5530 | Hig | 0.57 | 8.8 | 0.01 | Feb 18, 2020 | Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2013-2109 | Hig | 0.57 | 8.8 | 0.02 | Feb 10, 2020 | WordPress plugin wp-cleanfix has Remote Code Execution | ||
| CVE-2019-19659 | Hig | 0.57 | 8.8 | 0.00 | Feb 10, 2020 | A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html. | ||
| CVE-2019-20059 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2020 | payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the… | ||
| CVE-2011-1085 | Hig | 0.57 | 8.8 | 0.00 | Feb 7, 2020 | CSRF vulnerability in Smoothwall Express 3. | ||
| CVE-2012-6297 | Hig | 0.57 | 8.8 | 0.02 | Feb 6, 2020 | Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service. | ||
| CVE-2011-0525 | Hig | 0.57 | 8.8 | 0.01 | Feb 5, 2020 | Batavi before 1.0 has CSRF. | ||
| CVE-2019-4613 | Hig | 0.57 | 8.8 | 0.01 | Feb 5, 2020 | IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524. | ||
| CVE-2020-8420 | Hig | 0.57 | 8.8 | 0.01 | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability. | ||
| CVE-2020-8419 | Hig | 0.57 | 8.8 | 0.00 | Jan 28, 2020 | An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities. | ||
| CVE-2013-3093 | Hig | 0.57 | 8.8 | 0.01 | Jan 28, 2020 | ASUS RT-N56U devices allow CSRF. | ||
| CVE-2015-5483 | Hig | 0.57 | 8.8 | 0.02 | Jan 28, 2020 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or… | ||
| CVE-2019-16513 | Hig | 0.57 | 8.8 | 0.01 | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests. | ||
| CVE-2011-3612 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12. | ||
| CVE-2011-3582 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions. |
- risk 0.57cvss 8.8epss 0.01
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…
- risk 0.57cvss 8.8epss 0.01
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
- risk 0.57cvss 8.8epss 0.01
In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a…
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.02
WordPress plugin wp-cleanfix has Remote Code Execution
- risk 0.57cvss 8.8epss 0.00
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html.
- risk 0.57cvss 8.8epss 0.01
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the…
- risk 0.57cvss 8.8epss 0.00
CSRF vulnerability in Smoothwall Express 3.
- risk 0.57cvss 8.8epss 0.02
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
- risk 0.57cvss 8.8epss 0.01
Batavi before 1.0 has CSRF.
- risk 0.57cvss 8.8epss 0.01
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
- risk 0.57cvss 8.8epss 0.01
ASUS RT-N56U devices allow CSRF.
- risk 0.57cvss 8.8epss 0.02
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.
- risk 0.57cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
- risk 0.57cvss 8.8epss 0.01
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.