VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 72 of 482
  • CVE-2019-13056HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.

  • CVE-2019-7281HigJul 1, 2019
    risk 0.57cvss 8.8epss 0.01

    Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.

  • CVE-2019-12826HigJul 1, 2019
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility)…

  • CVE-2018-20848HigJun 30, 2019
    risk 0.57cvss 8.8epss 0.01

    Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.

  • CVE-2019-6166HigJun 26, 2019
    risk 0.57cvss 8.8epss 0.00

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.

  • CVE-2018-1858HigJun 25, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.

  • CVE-2019-9958HigJun 24, 2019
    risk 0.57cvss 8.8epss 0.01

    CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.

  • CVE-2019-12836HigJun 21, 2019
    risk 0.57cvss 8.8epss 0.01

    The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request that can be invoked in the context of an authenticated user,…

  • CVE-2019-1904HigJun 21, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an…

  • CVE-2019-1874HigJun 20, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protection…

  • CVE-2018-17387HigJun 19, 2019
    risk 0.57cvss 8.8epss 0.01

    CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.

  • CVE-2018-17389HigJun 19, 2019
    risk 0.57cvss 8.8epss 0.01

    CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.

  • CVE-2017-8328HigJun 18, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross site…

  • CVE-2018-18802HigJun 18, 2019
    risk 0.57cvss 8.8epss 0.01

    The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.

  • CVE-2019-4142HigJun 18, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338.

  • CVE-2017-9381HigJun 17, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deleting apps on the device using the web management interface. It seems that the device does not implement any cross-site request…

  • CVE-2019-6325HigJun 17, 2019
    risk 0.57cvss 8.8epss 0.01

    HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server that is potentially vulnerable to Cross-site Request Forgery.

  • CVE-2019-10338HigJun 11, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed attackers to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.

  • CVE-2018-10696HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions…

  • CVE-2019-9883HigJun 3, 2019
    risk 0.57cvss 8.8epss 0.01

    Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.