CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 76 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1003008 | Hig | 0.57 | 8.8 | 0.01 | Feb 6, 2019 | A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/analysis/warnings/groovy/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint. | ||
| CVE-2019-1000022 | Hig | 0.57 | 8.8 | 0.01 | Feb 4, 2019 | Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appears to be exploitable via malicious request against… | ||
| CVE-2019-1000003 | Hig | 0.57 | 8.8 | 0.01 | Feb 4, 2019 | MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via… | ||
| CVE-2019-7346 | Hig | 0.57 | 8.8 | 0.01 | Feb 4, 2019 | A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful. | ||
| CVE-2019-6510 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF. | ||
| CVE-2019-6509 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF. | ||
| CVE-2019-6508 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF. | ||
| CVE-2019-6507 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF. | ||
| CVE-2018-20728 | Hig | 0.57 | 8.8 | 0.01 | Jan 17, 2019 | A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php. | ||
| CVE-2016-10738 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2019 | Zenbership v107 has CSRF via admin/cp-functions/event-add.php. | ||
| CVE-2019-6294 | Hig | 0.57 | 8.8 | 0.01 | Jan 15, 2019 | An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI. | ||
| CVE-2019-6244 | Hig | 0.57 | 8.8 | 0.01 | Jan 12, 2019 | An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently execute arbitrary PHP code by writing that code into a .php file. | ||
| CVE-2018-20613 | Hig | 0.57 | 8.8 | 0.00 | Dec 30, 2018 | TEMMOKU T1.09 Beta allows admin/user/add CSRF. | ||
| CVE-2018-20612 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2018 | UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF. | ||
| CVE-2018-20603 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2018 | Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF. | ||
| CVE-2018-20598 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2018 | UCMS 1.4.7 has ?do=user_addpost CSRF. | ||
| CVE-2018-18696 | Hig | 0.57 | 8.8 | 0.01 | Dec 28, 2018 | main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?lang… | ||
| CVE-2018-20419 | Hig | 0.57 | 8.8 | 0.00 | Dec 24, 2018 | DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account. | ||
| CVE-2018-1000858 | Hig | 0.57 | 8.8 | 0.01 | Dec 20, 2018 | GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in… | ||
| CVE-2018-20231 | Hig | 0.57 | 8.8 | 0.01 | Dec 19, 2018 | Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation. |
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/analysis/warnings/groovy/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint.
- risk 0.57cvss 8.8epss 0.01
Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appears to be exploitable via malicious request against…
- risk 0.57cvss 8.8epss 0.01
MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via…
- risk 0.57cvss 8.8epss 0.01
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.
- risk 0.57cvss 8.8epss 0.01
A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.
- risk 0.57cvss 8.8epss 0.01
Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently execute arbitrary PHP code by writing that code into a .php file.
- risk 0.57cvss 8.8epss 0.00
TEMMOKU T1.09 Beta allows admin/user/add CSRF.
- risk 0.57cvss 8.8epss 0.01
UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.
- risk 0.57cvss 8.8epss 0.01
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.
- risk 0.57cvss 8.8epss 0.01
UCMS 1.4.7 has ?do=user_addpost CSRF.
- risk 0.57cvss 8.8epss 0.01
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?lang…
- risk 0.57cvss 8.8epss 0.00
DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.
- risk 0.57cvss 8.8epss 0.01
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in…
- risk 0.57cvss 8.8epss 0.01
Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation.