VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 64 of 482
  • CVE-2019-18206HigOct 30, 2019
    risk 0.57cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.

  • CVE-2019-9926HigOct 29, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability.

  • CVE-2010-4241HigOct 28, 2019
    risk 0.57cvss 8.8epss 0.01

    Tiki Wiki CMS Groupware 5.2 has CSRF

  • CVE-2013-4848HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.

  • CVE-2019-18414HigOct 24, 2019
    risk 0.57cvss 8.8epss 0.00

    Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a…

  • CVE-2019-12095HigOct 24, 2019
    risk 0.57cvss 8.8epss 0.01

    Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.

  • CVE-2019-18280HigOct 23, 2019
    risk 0.57cvss 8.8epss 0.00

    Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code via a crafted HTML page, as demonstrated by a Create User…

  • CVE-2019-18220HigOct 23, 2019
    risk 0.57cvss 8.8epss 0.01

    Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated…

  • CVE-2019-10468HigOct 23, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2019-10464HigOct 23, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file…

  • CVE-2015-9498HigOct 22, 2019
    risk 0.57cvss 8.8epss 0.01

    The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

  • CVE-2015-9497HigOct 22, 2019
    risk 0.57cvss 8.8epss 0.01

    The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

  • CVE-2019-17118HigOct 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal…

  • CVE-2019-17676HigOct 17, 2019
    risk 0.57cvss 8.8epss 0.01

    app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.

  • CVE-2019-12636HigOct 16, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2019-17593HigOct 14, 2019
    risk 0.57cvss 8.8epss 0.00

    JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.

  • CVE-2018-20582HigOct 11, 2019
    risk 0.57cvss 8.8epss 0.01

    The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.

  • CVE-2019-17495CriOct 10, 2019
    risk 0.57cvss 9.8epss 0.06

    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product…

  • CVE-2019-17386HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.01

    The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.

  • CVE-2019-17431HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.