VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 74 of 482
  • CVE-2019-11557HigApr 26, 2019
    risk 0.57cvss 8.8epss 0.01

    The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the…

  • CVE-2019-8991HigApr 24, 2019
    risk 0.57cvss 8.8epss 0.01

    The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for…

  • CVE-2019-11456HigApr 22, 2019
    risk 0.57cvss 8.8epss 0.01

    Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.

  • CVE-2019-3718HigApr 18, 2019
    risk 0.57cvss 8.8epss 0.01

    Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.

  • CVE-2019-1797HigApr 18, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the…

  • CVE-2018-16966HigApr 15, 2019
    risk 0.57cvss 8.8epss 0.01

    There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.

  • CVE-2018-17584HigApr 15, 2019
    risk 0.57cvss 8.8epss 0.01

    The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.

  • CVE-2019-11078HigApr 11, 2019
    risk 0.57cvss 8.8epss 0.01

    MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.

  • CVE-2019-11077HigApr 11, 2019
    risk 0.57cvss 8.8epss 0.01

    FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.

  • CVE-2019-0229HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.02

    A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site request forgery attacks.

  • CVE-2019-10888HigApr 5, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF Issue that can add an admin user was discovered in UKcms v1.1.10 via admin.php/admin/role/add.html.

  • CVE-2019-10673HigApr 3, 2019
    risk 0.57cvss 8.8epss 0.02

    A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the…

  • CVE-2014-7198HigApr 1, 2019
    risk 0.57cvss 8.8epss 0.01

    OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.

  • CVE-2019-10644HigMar 30, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.

  • CVE-2019-9604HigMar 29, 2019
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.

  • CVE-2019-10237HigMar 27, 2019
    risk 0.57cvss 8.8epss 0.01

    S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to CVE-2019-9040.

  • CVE-2019-7433HigMar 21, 2019
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

  • CVE-2018-20648HigMar 21, 2019
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.

  • CVE-2018-20644HigMar 21, 2019
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.

  • CVE-2018-20641HigMar 21, 2019
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.