VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 63 of 482
  • CVE-2019-16573HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2019-16570HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server.

  • CVE-2019-16565HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2019-16560HigDec 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.

  • CVE-2014-0197HigDec 13, 2019
    risk 0.57cvss 8.8epss 0.01

    CFME: CSRF protection vulnerability via permissive check of the referrer header

  • CVE-2019-15934HigDec 12, 2019
    risk 0.57cvss 8.8epss 0.01

    Intesync Solismed 3.3sp has CSRF.

  • CVE-2019-0398HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.00

    Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.

  • CVE-2019-19685HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.01

    RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

  • CVE-2019-18346HigDec 4, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add…

  • CVE-2019-19469HigDec 1, 2019
    risk 0.57cvss 8.8epss 0.01

    In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.

  • CVE-2019-17590HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.01

    The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social…

  • CVE-2013-6811HigNov 22, 2019
    risk 0.57cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom…

  • CVE-2012-2079HigNov 22, 2019
    risk 0.57cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

  • CVE-2013-3312HigNov 21, 2019
    risk 0.57cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to…

  • CVE-2013-3366HigNov 13, 2019
    risk 0.57cvss 8.8epss 0.01

    Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.

  • CVE-2019-18884HigNov 13, 2019
    risk 0.57cvss 8.8epss 0.01

    index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.

  • CVE-2010-3305HigNov 12, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.

  • CVE-2019-17237HigNov 12, 2019
    risk 0.57cvss 8.8epss 0.01

    includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.

  • CVE-2019-18411HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.02

    Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the…

  • CVE-2019-18650HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.