VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 70 of 482
  • CVE-2019-14703HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue was discovered in webparam?user&action=set&param=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to create an admin account.

  • CVE-2013-7473HigAug 1, 2019
    risk 0.57cvss 8.8epss 0.01

    Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.

  • CVE-2019-3959HigJul 31, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

  • CVE-2019-4212HigJul 25, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159132.

  • CVE-2019-11712HigJul 23, 2019
    risk 0.57cvss 8.8epss 0.01

    POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and…

  • CVE-2019-12934HigJul 20, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.

  • CVE-2018-17792HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.01

    MDaemon Webmail (formerly WorldClient) has CSRF.

  • CVE-2019-13974HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.01

    LayerBB 1.1.3 allows conversations.php/cmd/new CSRF.

  • CVE-2019-1010112HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.01

    OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3.

  • CVE-2019-9231HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and…

  • CVE-2019-13949HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.01

    SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.

  • CVE-2019-1010096HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.01

    DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html…

  • CVE-2019-1010095HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.01

    DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After the administrator logged in, open the html page.

  • CVE-2019-1010094HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.01

    domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The component is: http://127.0.0.1/settings/password/ http://127.0.0.1/admin/users/add.php http://127.0.0.1/admin/users/edit.php?uid=2…

  • CVE-2019-1010054HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.02

    Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack…

  • CVE-2019-13611HigJul 16, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.

  • CVE-2019-13563HigJul 11, 2019
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.

  • CVE-2019-12363HigJul 11, 2019
    risk 0.57cvss 8.8epss 0.01

    An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plugin to control its state via usercp.php?action=mybb2fa&do=deactivate (or usercp.php?action=mybb2fa&do=activate). A deactivate…

  • CVE-2019-12466HigJul 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Wikimedia MediaWiki through 1.32.1 allows CSRF.

  • CVE-2019-13071HigJul 10, 2019
    risk 0.57cvss 8.8epss 0.01

    CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.