CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 71 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12628 | Hig | 0.57 | 8.8 | 0.01 | Jul 10, 2019 | An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges. | ||
| CVE-2019-13401 | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. | ||
| CVE-2019-13183 | Hig | 0.57 | 8.8 | 0.01 | Jul 7, 2019 | Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. | ||
| CVE-2019-13370 | Hig | 0.57 | 8.8 | 0.01 | Jul 6, 2019 | index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator. | ||
| CVE-2019-5984 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5983 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5980 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5979 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5974 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5973 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5971 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5968 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'. | ||
| CVE-2019-5963 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5960 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-12851 | Hig | 0.57 | 8.8 | 0.01 | Jul 3, 2019 | A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852. | ||
| CVE-2018-10986 | Hig | 0.57 | 8.8 | 0.00 | Jul 3, 2019 | OX Guard 2.8.0 has CSRF. | ||
| CVE-2018-11427 | Hig | 0.57 | 8.8 | 0.01 | Jul 3, 2019 | CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator. | ||
| CVE-2017-8406 | Hig | 0.57 | 8.8 | 0.01 | Jul 2, 2019 | An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the device's webserver and pull any information that is stored on… | ||
| CVE-2017-8407 | Hig | 0.57 | 8.8 | 0.01 | Jul 2, 2019 | An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which… | ||
| CVE-2019-7270 | Hig | 0.57 | 8.8 | 0.01 | Jul 2, 2019 | Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF). |
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges.
- risk 0.57cvss 8.8epss 0.01
Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
- risk 0.57cvss 8.8epss 0.01
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
- risk 0.57cvss 8.8epss 0.01
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
- risk 0.57cvss 8.8epss 0.00
OX Guard 2.8.0 has CSRF.
- risk 0.57cvss 8.8epss 0.01
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the device's webserver and pull any information that is stored on…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which…
- risk 0.57cvss 8.8epss 0.01
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).