VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 75 of 482
  • CVE-2018-20633HigMar 21, 2019
    risk 0.57cvss 8.8epss 0.01

    PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

  • CVE-2019-5924HigMar 12, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.

  • CVE-2019-5920HigMar 12, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.

  • CVE-2019-9688HigMar 11, 2019
    risk 0.57cvss 8.8epss 0.01

    sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.

  • CVE-2019-9652HigMar 11, 2019
    risk 0.57cvss 8.8epss 0.01

    There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.

  • CVE-2019-8437HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.01

    njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.

  • CVE-2018-18449HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.01

    EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.

  • CVE-2018-17429HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.01

    /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.

  • CVE-2019-6561HigMar 5, 2019
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.

  • CVE-2019-9549HigMar 3, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.

  • CVE-2019-9182HigFeb 26, 2019
    risk 0.57cvss 8.8epss 0.01

    There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.

  • CVE-2019-9040HigFeb 23, 2019
    risk 0.57cvss 8.8epss 0.01

    S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332.

  • CVE-2019-8910HigFeb 18, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.

  • CVE-2019-0267HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external application.

  • CVE-2019-8347HigFeb 15, 2019
    risk 0.57cvss 8.8epss 0.01

    BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.

  • CVE-2019-7737HigFeb 11, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.

  • CVE-2018-20780HigFeb 11, 2019
    risk 0.57cvss 8.8epss 0.01

    Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).

  • CVE-2019-7569HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1.

  • CVE-2019-7566HigFeb 7, 2019
    risk 0.57cvss 8.8epss 0.01

    CSZ CMS 1.1.8 has CSRF via admin/users/new/add.

  • CVE-2019-1003016HigFeb 6, 2019
    risk 0.57cvss 8.8epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimport/JobImportGlobalConfig.java,…