CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 75 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20633 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2019 | PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. | ||
| CVE-2019-5924 | Hig | 0.57 | 8.8 | 0.01 | Mar 12, 2019 | Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page. | ||
| CVE-2019-5920 | Hig | 0.57 | 8.8 | 0.01 | Mar 12, 2019 | Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page. | ||
| CVE-2019-9688 | Hig | 0.57 | 8.8 | 0.01 | Mar 11, 2019 | sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account. | ||
| CVE-2019-9652 | Hig | 0.57 | 8.8 | 0.01 | Mar 11, 2019 | There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter. | ||
| CVE-2019-8437 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2019 | njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator. | ||
| CVE-2018-18449 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2019 | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339. | ||
| CVE-2018-17429 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2019 | /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account. | ||
| CVE-2019-6561 | Hig | 0.57 | 8.8 | 0.01 | Mar 5, 2019 | Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device. | ||
| CVE-2019-9549 | Hig | 0.57 | 8.8 | 0.01 | Mar 3, 2019 | An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935. | ||
| CVE-2019-9182 | Hig | 0.57 | 8.8 | 0.01 | Feb 26, 2019 | There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter. | ||
| CVE-2019-9040 | Hig | 0.57 | 8.8 | 0.01 | Feb 23, 2019 | S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332. | ||
| CVE-2019-8910 | Hig | 0.57 | 8.8 | 0.01 | Feb 18, 2019 | An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF. | ||
| CVE-2019-0267 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2019 | SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application. | ||
| CVE-2019-8347 | Hig | 0.57 | 8.8 | 0.01 | Feb 15, 2019 | BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI. | ||
| CVE-2019-7737 | Hig | 0.57 | 8.8 | 0.01 | Feb 11, 2019 | A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit. | ||
| CVE-2018-20780 | Hig | 0.57 | 8.8 | 0.01 | Feb 11, 2019 | Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1). | ||
| CVE-2019-7569 | Hig | 0.57 | 8.8 | 0.01 | Feb 7, 2019 | An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1. | ||
| CVE-2019-7566 | Hig | 0.57 | 8.8 | 0.01 | Feb 7, 2019 | CSZ CMS 1.1.8 has CSRF via admin/users/new/add. | ||
| CVE-2019-1003016 | Hig | 0.57 | 8.8 | 0.01 | Feb 6, 2019 | An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimport/JobImportGlobalConfig.java,… |
- risk 0.57cvss 8.8epss 0.01
PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
- risk 0.57cvss 8.8epss 0.01
sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.
- risk 0.57cvss 8.8epss 0.01
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.
- risk 0.57cvss 8.8epss 0.01
njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.
- risk 0.57cvss 8.8epss 0.01
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
- risk 0.57cvss 8.8epss 0.01
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.
- risk 0.57cvss 8.8epss 0.01
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.
- risk 0.57cvss 8.8epss 0.01
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
- risk 0.57cvss 8.8epss 0.01
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.
- risk 0.57cvss 8.8epss 0.01
BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.
- risk 0.57cvss 8.8epss 0.01
A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.
- risk 0.57cvss 8.8epss 0.01
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1.
- risk 0.57cvss 8.8epss 0.01
CSZ CMS 1.1.8 has CSRF via admin/users/new/add.
- risk 0.57cvss 8.8epss 0.01
An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimport/JobImportGlobalConfig.java,…