CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 72 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13056 | Hig | 0.57 | 8.8 | 0.01 | Jul 2, 2019 | An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection. | ||
| CVE-2019-7281 | Hig | 0.57 | 8.8 | 0.01 | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website. | ||
| CVE-2019-12826 | Hig | 0.57 | 8.8 | 0.01 | Jul 1, 2019 | A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility)… | ||
| CVE-2018-20848 | Hig | 0.57 | 8.8 | 0.01 | Jun 30, 2019 | Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter. | ||
| CVE-2019-6166 | Hig | 0.57 | 8.8 | 0.00 | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. | ||
| CVE-2018-1858 | Hig | 0.57 | 8.8 | 0.01 | Jun 25, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256. | ||
| CVE-2019-9958 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2019 | CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests. | ||
| CVE-2019-12836 | Hig | 0.57 | 8.8 | 0.01 | Jun 21, 2019 | The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request that can be invoked in the context of an authenticated user,… | ||
| CVE-2019-1904 | Hig | 0.57 | 8.8 | 0.01 | Jun 21, 2019 | A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an… | ||
| CVE-2019-1874 | Hig | 0.57 | 8.8 | 0.01 | Jun 20, 2019 | A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protection… | ||
| CVE-2018-17387 | Hig | 0.57 | 8.8 | 0.01 | Jun 19, 2019 | CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account. | ||
| CVE-2018-17389 | Hig | 0.57 | 8.8 | 0.01 | Jun 19, 2019 | CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. | ||
| CVE-2017-8328 | Hig | 0.57 | 8.8 | 0.01 | Jun 18, 2019 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross site… | ||
| CVE-2018-18802 | Hig | 0.57 | 8.8 | 0.01 | Jun 18, 2019 | The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit. | ||
| CVE-2019-4142 | Hig | 0.57 | 8.8 | 0.01 | Jun 18, 2019 | IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338. | ||
| CVE-2017-9381 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2019 | An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deleting apps on the device using the web management interface. It seems that the device does not implement any cross-site request… | ||
| CVE-2019-6325 | Hig | 0.57 | 8.8 | 0.01 | Jun 17, 2019 | HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server that is potentially vulnerable to Cross-site Request Forgery. | ||
| CVE-2019-10338 | Hig | 0.57 | 8.8 | 0.01 | Jun 11, 2019 | A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed attackers to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials. | ||
| CVE-2018-10696 | Hig | 0.57 | 8.8 | 0.01 | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions… | ||
| CVE-2019-9883 | Hig | 0.57 | 8.8 | 0.01 | Jun 3, 2019 | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes. |
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.
- risk 0.57cvss 8.8epss 0.01
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
- risk 0.57cvss 8.8epss 0.01
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility)…
- risk 0.57cvss 8.8epss 0.01
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.
- risk 0.57cvss 8.8epss 0.00
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
- risk 0.57cvss 8.8epss 0.01
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.
- risk 0.57cvss 8.8epss 0.01
CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.
- risk 0.57cvss 8.8epss 0.01
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request that can be invoked in the context of an authenticated user,…
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an…
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protection…
- risk 0.57cvss 8.8epss 0.01
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
- risk 0.57cvss 8.8epss 0.01
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross site…
- risk 0.57cvss 8.8epss 0.01
The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.
- risk 0.57cvss 8.8epss 0.01
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deleting apps on the device using the web management interface. It seems that the device does not implement any cross-site request…
- risk 0.57cvss 8.8epss 0.01
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server that is potentially vulnerable to Cross-site Request Forgery.
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed attackers to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions…
- risk 0.57cvss 8.8epss 0.01
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.