VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 71 of 482
  • CVE-2018-12628HigJul 10, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges.

  • CVE-2019-13401HigJul 8, 2019
    risk 0.57cvss 8.8epss 0.01

    Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.

  • CVE-2019-13183HigJul 7, 2019
    risk 0.57cvss 8.8epss 0.01

    Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.

  • CVE-2019-13370HigJul 6, 2019
    risk 0.57cvss 8.8epss 0.01

    index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.

  • CVE-2019-5984HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5983HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5980HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5979HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5974HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5973HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5971HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5968HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.

  • CVE-2019-5963HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-5960HigJul 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

  • CVE-2019-12851HigJul 3, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

  • CVE-2018-10986HigJul 3, 2019
    risk 0.57cvss 8.8epss 0.00

    OX Guard 2.8.0 has CSRF.

  • CVE-2018-11427HigJul 3, 2019
    risk 0.57cvss 8.8epss 0.01

    CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.

  • CVE-2017-8406HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the device's webserver and pull any information that is stored on…

  • CVE-2017-8407HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which…

  • CVE-2019-7270HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.01

    Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).