CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 78 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-6907 | Hig | 0.57 | 8.8 | 0.00 | Nov 1, 2018 | A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API. | ||
| CVE-2018-18842 | Hig | 0.57 | 8.8 | 0.01 | Oct 30, 2018 | CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code. | ||
| CVE-2018-18742 | Hig | 0.57 | 8.8 | 0.01 | Oct 29, 2018 | A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI. | ||
| CVE-2018-18735 | Hig | 0.57 | 8.8 | 0.01 | Oct 29, 2018 | A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33. | ||
| CVE-2018-18734 | Hig | 0.57 | 8.8 | 0.00 | Oct 29, 2018 | A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30. | ||
| CVE-2018-18712 | Hig | 0.57 | 8.8 | 0.01 | Oct 29, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1. | ||
| CVE-2018-18711 | Hig | 0.57 | 8.8 | 0.01 | Oct 29, 2018 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info. | ||
| CVE-2018-9281 | Hig | 0.57 | 8.8 | 0.00 | Oct 24, 2018 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are… | ||
| CVE-2018-18420 | Hig | 0.57 | 8.8 | 0.01 | Oct 19, 2018 | Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI. | ||
| CVE-2018-12370 | Hig | 0.57 | 8.8 | 0.01 | Oct 18, 2018 | In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61. | ||
| CVE-2018-12364 | Hig | 0.57 | 8.8 | 0.02 | Oct 18, 2018 | NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability… | ||
| CVE-2018-18436 | Hig | 0.57 | 8.8 | 0.01 | Oct 17, 2018 | JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI. | ||
| CVE-2018-18432 | Hig | 0.57 | 8.8 | 0.01 | Oct 17, 2018 | An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request. | ||
| CVE-2018-18422 | Hig | 0.57 | 8.8 | 0.00 | Oct 17, 2018 | UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI. | ||
| CVE-2018-15539 | Hig | 0.57 | 8.8 | 0.01 | Oct 15, 2018 | Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc. | ||
| CVE-2018-18317 | Hig | 0.57 | 8.8 | 0.00 | Oct 15, 2018 | DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI. | ||
| CVE-2018-18316 | Hig | 0.57 | 8.8 | 0.01 | Oct 15, 2018 | emlog v6.0.0 has CSRF via the admin/user.php?action=new URI. | ||
| CVE-2018-18215 | Hig | 0.57 | 8.8 | 0.00 | Oct 11, 2018 | In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account. | ||
| CVE-2018-12456 | Hig | 0.57 | 8.8 | 0.01 | Oct 10, 2018 | Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access. | ||
| CVE-2018-18201 | Hig | 0.57 | 8.8 | 0.00 | Oct 9, 2018 | qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account. |
- risk 0.57cvss 8.8epss 0.00
A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API.
- risk 0.57cvss 8.8epss 0.01
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.
- risk 0.57cvss 8.8epss 0.01
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
- risk 0.57cvss 8.8epss 0.01
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
- risk 0.57cvss 8.8epss 0.00
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are…
- risk 0.57cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI.
- risk 0.57cvss 8.8epss 0.01
In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61.
- risk 0.57cvss 8.8epss 0.02
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability…
- risk 0.57cvss 8.8epss 0.01
JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.
- risk 0.57cvss 8.8epss 0.00
UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.
- risk 0.57cvss 8.8epss 0.01
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
- risk 0.57cvss 8.8epss 0.00
DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.
- risk 0.57cvss 8.8epss 0.01
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
- risk 0.57cvss 8.8epss 0.00
In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.
- risk 0.57cvss 8.8epss 0.01
Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access.
- risk 0.57cvss 8.8epss 0.00
qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.