VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 77 of 482
  • CVE-2018-20188HigDec 17, 2018
    risk 0.57cvss 8.8epss 0.01

    FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

  • CVE-2018-19969HigDec 11, 2018
    risk 0.57cvss 8.8epss 0.01

    phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages,…

  • CVE-2018-20015HigDec 10, 2018
    risk 0.57cvss 8.8epss 0.01

    YzmCMS v5.2 has admin/role/add.html CSRF.

  • CVE-2018-19923HigDec 6, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.

  • CVE-2018-16634HigDec 4, 2018
    risk 0.57cvss 8.8epss 0.01

    Pluck v4.7.7 allows CSRF via admin.php?action=settings.

  • CVE-2018-7831HigNov 30, 2018
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web…

  • CVE-2018-14892HigNov 27, 2018
    risk 0.57cvss 8.8epss 0.01

    Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms.

  • CVE-2018-19561HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.00

    sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.

  • CVE-2018-19560HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.01

    BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

  • CVE-2018-19555HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.01

    tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.

  • CVE-2018-19546HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.01

    JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.

  • CVE-2018-19545HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.00

    JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.

  • CVE-2018-19332HigNov 17, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.

  • CVE-2018-19327HigNov 17, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.

  • CVE-2018-19318HigNov 16, 2018
    risk 0.57cvss 8.8epss 0.00

    SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.

  • CVE-2018-19225HigNov 12, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF.

  • CVE-2018-19192HigNov 12, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.

  • CVE-2017-17550HigNov 10, 2018
    risk 0.57cvss 8.8epss 0.00

    ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.

  • CVE-2018-19104HigNov 8, 2018
    risk 0.57cvss 8.8epss 0.01

    In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.

  • CVE-2018-18935HigNov 5, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.