CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 70 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14703 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | A CSRF issue was discovered in webparam?user&action=set¶m=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to create an admin account. | ||
| CVE-2013-7473 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account. | ||
| CVE-2019-3959 | Hig | 0.57 | 8.8 | 0.01 | Jul 31, 2019 | Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | ||
| CVE-2019-4212 | Hig | 0.57 | 8.8 | 0.01 | Jul 25, 2019 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159132. | ||
| CVE-2019-11712 | Hig | 0.57 | 8.8 | 0.01 | Jul 23, 2019 | POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and… | ||
| CVE-2019-12934 | Hig | 0.57 | 8.8 | 0.01 | Jul 20, 2019 | An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter. | ||
| CVE-2018-17792 | Hig | 0.57 | 8.8 | 0.01 | Jul 19, 2019 | MDaemon Webmail (formerly WorldClient) has CSRF. | ||
| CVE-2019-13974 | Hig | 0.57 | 8.8 | 0.01 | Jul 19, 2019 | LayerBB 1.1.3 allows conversations.php/cmd/new CSRF. | ||
| CVE-2019-1010112 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2019 | OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3. | ||
| CVE-2019-9231 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2019 | An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and… | ||
| CVE-2019-13949 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2019 | SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change. | ||
| CVE-2019-1010096 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2019 | DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html… | ||
| CVE-2019-1010095 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2019 | DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After the administrator logged in, open the html page. | ||
| CVE-2019-1010094 | Hig | 0.57 | 8.8 | 0.01 | Jul 18, 2019 | domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The component is: http://127.0.0.1/settings/password/ http://127.0.0.1/admin/users/add.php http://127.0.0.1/admin/users/edit.php?uid=2… | ||
| CVE-2019-1010054 | Hig | 0.57 | 8.8 | 0.02 | Jul 18, 2019 | Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack… | ||
| CVE-2019-13611 | Hig | 0.57 | 8.8 | 0.01 | Jul 16, 2019 | An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted. | ||
| CVE-2019-13563 | Hig | 0.57 | 8.8 | 0.01 | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console. | ||
| CVE-2019-12363 | Hig | 0.57 | 8.8 | 0.01 | Jul 11, 2019 | An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plugin to control its state via usercp.php?action=mybb2fa&do=deactivate (or usercp.php?action=mybb2fa&do=activate). A deactivate… | ||
| CVE-2019-12466 | Hig | 0.57 | 8.8 | 0.01 | Jul 10, 2019 | Wikimedia MediaWiki through 1.32.1 allows CSRF. | ||
| CVE-2019-13071 | Hig | 0.57 | 8.8 | 0.01 | Jul 10, 2019 | CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page. |
- risk 0.57cvss 8.8epss 0.01
A CSRF issue was discovered in webparam?user&action=set¶m=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to create an admin account.
- risk 0.57cvss 8.8epss 0.01
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
- risk 0.57cvss 8.8epss 0.01
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159132.
- risk 0.57cvss 8.8epss 0.01
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
- risk 0.57cvss 8.8epss 0.01
MDaemon Webmail (formerly WorldClient) has CSRF.
- risk 0.57cvss 8.8epss 0.01
LayerBB 1.1.3 allows conversations.php/cmd/new CSRF.
- risk 0.57cvss 8.8epss 0.01
OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and…
- risk 0.57cvss 8.8epss 0.01
SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.
- risk 0.57cvss 8.8epss 0.01
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html…
- risk 0.57cvss 8.8epss 0.01
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After the administrator logged in, open the html page.
- risk 0.57cvss 8.8epss 0.01
domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The component is: http://127.0.0.1/settings/password/ http://127.0.0.1/admin/users/add.php http://127.0.0.1/admin/users/edit.php?uid=2…
- risk 0.57cvss 8.8epss 0.02
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
- risk 0.57cvss 8.8epss 0.01
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
- risk 0.57cvss 8.8epss 0.01
An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plugin to control its state via usercp.php?action=mybb2fa&do=deactivate (or usercp.php?action=mybb2fa&do=activate). A deactivate…
- risk 0.57cvss 8.8epss 0.01
Wikimedia MediaWiki through 1.32.1 allows CSRF.
- risk 0.57cvss 8.8epss 0.01
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.