CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 77 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20188 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2018 | FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account. | ||
| CVE-2018-19969 | Hig | 0.57 | 8.8 | 0.01 | Dec 11, 2018 | phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages,… | ||
| CVE-2018-20015 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2018 | YzmCMS v5.2 has admin/role/add.html CSRF. | ||
| CVE-2018-19923 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF. | ||
| CVE-2018-16634 | Hig | 0.57 | 8.8 | 0.01 | Dec 4, 2018 | Pluck v4.7.7 allows CSRF via admin.php?action=settings. | ||
| CVE-2018-7831 | Hig | 0.57 | 8.8 | 0.01 | Nov 30, 2018 | An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web… | ||
| CVE-2018-14892 | Hig | 0.57 | 8.8 | 0.01 | Nov 27, 2018 | Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms. | ||
| CVE-2018-19561 | Hig | 0.57 | 8.8 | 0.00 | Nov 26, 2018 | sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account. | ||
| CVE-2018-19560 | Hig | 0.57 | 8.8 | 0.01 | Nov 26, 2018 | BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account. | ||
| CVE-2018-19555 | — | Hig | 0.57 | 8.8 | 0.01 | Nov 26, 2018 | tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password. | |
| CVE-2018-19546 | Hig | 0.57 | 8.8 | 0.01 | Nov 26, 2018 | JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter. | ||
| CVE-2018-19545 | Hig | 0.57 | 8.8 | 0.00 | Nov 26, 2018 | JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. | ||
| CVE-2018-19332 | Hig | 0.57 | 8.8 | 0.00 | Nov 17, 2018 | An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI. | ||
| CVE-2018-19327 | Hig | 0.57 | 8.8 | 0.00 | Nov 17, 2018 | An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF. | ||
| CVE-2018-19318 | Hig | 0.57 | 8.8 | 0.00 | Nov 16, 2018 | SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account. | ||
| CVE-2018-19225 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF. | ||
| CVE-2018-19192 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter. | ||
| CVE-2017-17550 | Hig | 0.57 | 8.8 | 0.00 | Nov 10, 2018 | ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS. | ||
| CVE-2018-19104 | Hig | 0.57 | 8.8 | 0.01 | Nov 8, 2018 | In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges. | ||
| CVE-2018-18935 | Hig | 0.57 | 8.8 | 0.01 | Nov 5, 2018 | An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account. |
- risk 0.57cvss 8.8epss 0.01
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
- risk 0.57cvss 8.8epss 0.01
phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages,…
- risk 0.57cvss 8.8epss 0.01
YzmCMS v5.2 has admin/role/add.html CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
- risk 0.57cvss 8.8epss 0.01
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
- risk 0.57cvss 8.8epss 0.01
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web…
- risk 0.57cvss 8.8epss 0.01
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms.
- risk 0.57cvss 8.8epss 0.00
sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.
- risk 0.57cvss 8.8epss 0.01
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
- risk 0.57cvss 8.8epss 0.01
tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.
- risk 0.57cvss 8.8epss 0.01
JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.
- risk 0.57cvss 8.8epss 0.00
JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.
- risk 0.57cvss 8.8epss 0.00
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.
- risk 0.57cvss 8.8epss 0.00
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.
- risk 0.57cvss 8.8epss 0.01
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.