VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 73 of 482
  • CVE-2019-9882HigJun 3, 2019
    risk 0.57cvss 8.8epss 0.01

    Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&[email protected]&new_memo=&add=%E6%96%B0%E5%A2…

  • CVE-2019-12502HigMay 31, 2019
    risk 0.57cvss 8.8epss 0.01

    There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.

  • CVE-2018-16218HigMay 29, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote attacker to trigger code execution or settings modification on the device by providing a crafted link to the victim.

  • CVE-2016-10757HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.01

    In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.

  • CVE-2016-10756HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.01

    Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.

  • CVE-2018-7828HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into the camera.

  • CVE-2018-16136HigMay 13, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission of multiple forms unwillingly by a victim.

  • CVE-2019-11886HigMay 13, 2019
    risk 0.57cvss 8.8epss 0.02

    The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

  • CVE-2017-12789HigMay 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

  • CVE-2018-13993HigMay 7, 2019
    risk 0.57cvss 8.8epss 0.01

    The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.

  • CVE-2018-4066HigMay 6, 2019
    risk 0.57cvss 8.8epss 0.02

    An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated…

  • CVE-2019-5430HigMay 6, 2019
    risk 0.57cvss 8.8epss 0.01

    In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.

  • CVE-2019-11617HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.01

    doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.

  • CVE-2018-15206HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.01

    BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.

  • CVE-2018-14930HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP URI.

  • CVE-2019-10315HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.02

    Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF.

  • CVE-2019-10310HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.02

    A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using…

  • CVE-2018-5123HigApr 29, 2019
    risk 0.57cvss 8.8epss 0.01

    A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4.

  • CVE-2019-11591HigApr 29, 2019
    risk 0.57cvss 8.8epss 0.01

    The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action']…

  • CVE-2019-11590HigApr 29, 2019
    risk 0.57cvss 8.8epss 0.01

    The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value,…