CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 63 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16573 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||
| CVE-2019-16570 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server. | ||
| CVE-2019-16565 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||
| CVE-2019-16560 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. | ||
| CVE-2014-0197 | Hig | 0.57 | 8.8 | 0.01 | Dec 13, 2019 | CFME: CSRF protection vulnerability via permissive check of the referrer header | ||
| CVE-2019-15934 | Hig | 0.57 | 8.8 | 0.01 | Dec 12, 2019 | Intesync Solismed 3.3sp has CSRF. | ||
| CVE-2019-0398 | Hig | 0.57 | 8.8 | 0.00 | Dec 11, 2019 | Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery. | ||
| CVE-2019-19685 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2019 | RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions. | ||
| CVE-2019-18346 | Hig | 0.57 | 8.8 | 0.01 | Dec 4, 2019 | A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add… | ||
| CVE-2019-19469 | Hig | 0.57 | 8.8 | 0.01 | Dec 1, 2019 | In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials. | ||
| CVE-2019-17590 | Hig | 0.57 | 8.8 | 0.01 | Nov 26, 2019 | The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social… | ||
| CVE-2013-6811 | Hig | 0.57 | 8.8 | 0.01 | Nov 22, 2019 | Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom… | ||
| CVE-2012-2079 | Hig | 0.57 | 8.8 | 0.00 | Nov 22, 2019 | A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. | ||
| CVE-2013-3312 | Hig | 0.57 | 8.8 | 0.01 | Nov 21, 2019 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to… | ||
| CVE-2013-3366 | Hig | 0.57 | 8.8 | 0.01 | Nov 13, 2019 | Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3. | ||
| CVE-2019-18884 | Hig | 0.57 | 8.8 | 0.01 | Nov 13, 2019 | index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users. | ||
| CVE-2010-3305 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2019 | Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password. | ||
| CVE-2019-17237 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2019 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. | ||
| CVE-2019-18411 | Hig | 0.57 | 8.8 | 0.02 | Nov 6, 2019 | Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the… | ||
| CVE-2019-18650 | Hig | 0.57 | 8.8 | 0.00 | Nov 6, 2019 | An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability. |
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.
- risk 0.57cvss 8.8epss 0.01
CFME: CSRF protection vulnerability via permissive check of the referrer header
- risk 0.57cvss 8.8epss 0.01
Intesync Solismed 3.3sp has CSRF.
- risk 0.57cvss 8.8epss 0.00
Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
- risk 0.57cvss 8.8epss 0.01
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
- risk 0.57cvss 8.8epss 0.01
A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add…
- risk 0.57cvss 8.8epss 0.01
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.
- risk 0.57cvss 8.8epss 0.01
The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social…
- risk 0.57cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom…
- risk 0.57cvss 8.8epss 0.00
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
- risk 0.57cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to…
- risk 0.57cvss 8.8epss 0.01
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
- risk 0.57cvss 8.8epss 0.01
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
- risk 0.57cvss 8.8epss 0.01
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
- risk 0.57cvss 8.8epss 0.02
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the…
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.