VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 76 of 482
  • CVE-2019-1003008HigFeb 6, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/analysis/warnings/groovy/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint.

  • CVE-2019-1000022HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.01

    Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appears to be exploitable via malicious request against…

  • CVE-2019-1000003HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.01

    MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via…

  • CVE-2019-7346HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.

  • CVE-2019-6510HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.

  • CVE-2019-6509HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.

  • CVE-2019-6508HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.

  • CVE-2019-6507HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.

  • CVE-2018-20728HigJan 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.

  • CVE-2016-10738HigJan 16, 2019
    risk 0.57cvss 8.8epss 0.01

    Zenbership v107 has CSRF via admin/cp-functions/event-add.php.

  • CVE-2019-6294HigJan 15, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.

  • CVE-2019-6244HigJan 12, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently execute arbitrary PHP code by writing that code into a .php file.

  • CVE-2018-20613HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.00

    TEMMOKU T1.09 Beta allows admin/user/add CSRF.

  • CVE-2018-20612HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.01

    UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.

  • CVE-2018-20603HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.01

    Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.

  • CVE-2018-20598HigDec 30, 2018
    risk 0.57cvss 8.8epss 0.01

    UCMS 1.4.7 has ?do=user_addpost CSRF.

  • CVE-2018-18696HigDec 28, 2018
    risk 0.57cvss 8.8epss 0.01

    main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?lang…

  • CVE-2018-20419HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.00

    DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.

  • CVE-2018-1000858HigDec 20, 2018
    risk 0.57cvss 8.8epss 0.01

    GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in…

  • CVE-2018-20231HigDec 19, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation.