CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 64 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18206 | Hig | 0.57 | 8.8 | 0.00 | Oct 30, 2019 | A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload. | ||
| CVE-2019-9926 | Hig | 0.57 | 8.8 | 0.02 | Oct 29, 2019 | An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability. | ||
| CVE-2010-4241 | Hig | 0.57 | 8.8 | 0.01 | Oct 28, 2019 | Tiki Wiki CMS Groupware 5.2 has CSRF | ||
| CVE-2013-4848 | Hig | 0.57 | 8.8 | 0.01 | Oct 25, 2019 | TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities. | ||
| CVE-2019-18414 | Hig | 0.57 | 8.8 | 0.00 | Oct 24, 2019 | Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a… | ||
| CVE-2019-12095 | Hig | 0.57 | 8.8 | 0.01 | Oct 24, 2019 | Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload. | ||
| CVE-2019-18280 | Hig | 0.57 | 8.8 | 0.00 | Oct 23, 2019 | Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code via a crafted HTML page, as demonstrated by a Create User… | ||
| CVE-2019-18220 | Hig | 0.57 | 8.8 | 0.01 | Oct 23, 2019 | Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated… | ||
| CVE-2019-10468 | Hig | 0.57 | 8.8 | 0.01 | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||
| CVE-2019-10464 | Hig | 0.57 | 8.8 | 0.01 | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file… | ||
| CVE-2015-9498 | Hig | 0.57 | 8.8 | 0.01 | Oct 22, 2019 | The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value. | ||
| CVE-2015-9497 | Hig | 0.57 | 8.8 | 0.01 | Oct 22, 2019 | The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. | ||
| CVE-2019-17118 | Hig | 0.57 | 8.8 | 0.01 | Oct 17, 2019 | A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal… | ||
| CVE-2019-17676 | Hig | 0.57 | 8.8 | 0.01 | Oct 17, 2019 | app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI. | ||
| CVE-2019-12636 | Hig | 0.57 | 8.8 | 0.01 | Oct 16, 2019 | A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF… | ||
| CVE-2019-17593 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2019 | JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator. | ||
| CVE-2018-20582 | Hig | 0.57 | 8.8 | 0.01 | Oct 11, 2019 | The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery. | ||
| CVE-2019-17495 | Cri | 0.57 | 9.8 | 0.06 | Oct 10, 2019 | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product… | ||
| CVE-2019-17386 | Hig | 0.57 | 8.8 | 0.01 | Oct 10, 2019 | The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php. | ||
| CVE-2019-17431 | Hig | 0.57 | 8.8 | 0.01 | Oct 10, 2019 | An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability. |
- risk 0.57cvss 8.8epss 0.00
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability.
- risk 0.57cvss 8.8epss 0.01
Tiki Wiki CMS Groupware 5.2 has CSRF
- risk 0.57cvss 8.8epss 0.01
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
- risk 0.57cvss 8.8epss 0.00
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a…
- risk 0.57cvss 8.8epss 0.01
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.
- risk 0.57cvss 8.8epss 0.00
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code via a crafted HTML page, as demonstrated by a Create User…
- risk 0.57cvss 8.8epss 0.01
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated…
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file…
- risk 0.57cvss 8.8epss 0.01
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
- risk 0.57cvss 8.8epss 0.01
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
- risk 0.57cvss 8.8epss 0.01
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal…
- risk 0.57cvss 8.8epss 0.01
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…
- risk 0.57cvss 8.8epss 0.00
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
- risk 0.57cvss 8.8epss 0.01
The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.
- risk 0.57cvss 9.8epss 0.06
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product…
- risk 0.57cvss 8.8epss 0.01
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.