VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 78 of 482
  • CVE-2018-6907HigNov 1, 2018
    risk 0.57cvss 8.8epss 0.00

    A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API.

  • CVE-2018-18842HigOct 30, 2018
    risk 0.57cvss 8.8epss 0.01

    CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.

  • CVE-2018-18742HigOct 29, 2018
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.

  • CVE-2018-18735HigOct 29, 2018
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

  • CVE-2018-18734HigOct 29, 2018
    risk 0.57cvss 8.8epss 0.00

    A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

  • CVE-2018-18712HigOct 29, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.

  • CVE-2018-18711HigOct 29, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.

  • CVE-2018-9281HigOct 24, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are…

  • CVE-2018-18420HigOct 19, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI.

  • CVE-2018-12370HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.01

    In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61.

  • CVE-2018-12364HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.02

    NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability…

  • CVE-2018-18436HigOct 17, 2018
    risk 0.57cvss 8.8epss 0.01

    JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.

  • CVE-2018-18432HigOct 17, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.

  • CVE-2018-18422HigOct 17, 2018
    risk 0.57cvss 8.8epss 0.00

    UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.

  • CVE-2018-15539HigOct 15, 2018
    risk 0.57cvss 8.8epss 0.01

    Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.

  • CVE-2018-18317HigOct 15, 2018
    risk 0.57cvss 8.8epss 0.00

    DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.

  • CVE-2018-18316HigOct 15, 2018
    risk 0.57cvss 8.8epss 0.01

    emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.

  • CVE-2018-18215HigOct 11, 2018
    risk 0.57cvss 8.8epss 0.00

    In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.

  • CVE-2018-12456HigOct 10, 2018
    risk 0.57cvss 8.8epss 0.01

    Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access.

  • CVE-2018-18201HigOct 9, 2018
    risk 0.57cvss 8.8epss 0.00

    qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.