CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 8 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15046 | Hig | 0.60 | 8.8 | 0.02 | Jun 24, 2020 | The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88. | ||
| CVE-2019-16068 | Hig | 0.60 | 8.8 | 0.01 | Mar 19, 2020 | A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site. | ||
| CVE-2012-2629 | Hig | 0.60 | 8.8 | 0.02 | Feb 20, 2020 | Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to… | ||
| CVE-2014-2225 | Hig | 0.60 | 8.8 | 0.01 | Feb 8, 2020 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified… | ||
| CVE-2014-5288 | Hig | 0.60 | 8.8 | 0.02 | Feb 7, 2020 | A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages. | ||
| CVE-2013-7053 | Hig | 0.60 | 8.8 | 0.03 | Feb 4, 2020 | D-Link DIR-100 4.03B07: cli.cgi CSRF | ||
| CVE-2020-8424 | Hig | 0.60 | 8.8 | 0.02 | Jan 28, 2020 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php. | ||
| CVE-2020-7991 | Hig | 0.60 | 8.8 | 0.03 | Jan 26, 2020 | Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. | ||
| CVE-2014-3136 | Hig | 0.60 | 8.8 | 0.03 | Dec 27, 2019 | Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors. | ||
| CVE-2015-3140 | Hig | 0.60 | 8.8 | 0.01 | Nov 21, 2019 | Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567 | ||
| CVE-2019-13529 | Hig | 0.60 | 8.8 | 0.03 | Oct 9, 2019 | An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a… | ||
| CVE-2019-14346 | Hig | 0.60 | 8.8 | 0.03 | Aug 6, 2019 | Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password. | ||
| CVE-2019-14328 | Hig | 0.60 | 8.8 | 0.03 | Jul 28, 2019 | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | ||
| CVE-2019-13961 | Hig | 0.60 | 8.8 | 0.02 | Jul 18, 2019 | A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php. | ||
| CVE-2019-10847 | Hig | 0.60 | 8.8 | 0.02 | May 24, 2019 | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. | ||
| CVE-2019-11569 | Hig | 0.60 | 8.8 | 0.02 | May 6, 2019 | Veeam ONE Reporter 9.5.0.3201 allows CSRF. | ||
| CVE-2019-6282 | Hig | 0.60 | 8.8 | 0.03 | Mar 21, 2019 | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password. | ||
| CVE-2018-14575 | Hig | 0.60 | 8.8 | 0.02 | Mar 21, 2019 | Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject. | ||
| CVE-2019-9769 | Hig | 0.60 | 8.8 | 0.02 | Mar 14, 2019 | PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator. | ||
| CVE-2019-6710 | Hig | 0.60 | 8.8 | 0.03 | Mar 7, 2019 | Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. |
- risk 0.60cvss 8.8epss 0.02
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
- risk 0.60cvss 8.8epss 0.01
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site.
- risk 0.60cvss 8.8epss 0.02
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to…
- risk 0.60cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified…
- risk 0.60cvss 8.8epss 0.02
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
- risk 0.60cvss 8.8epss 0.03
D-Link DIR-100 4.03B07: cli.cgi CSRF
- risk 0.60cvss 8.8epss 0.02
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
- risk 0.60cvss 8.8epss 0.03
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
- risk 0.60cvss 8.8epss 0.03
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors.
- risk 0.60cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567
- risk 0.60cvss 8.8epss 0.03
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a…
- risk 0.60cvss 8.8epss 0.03
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
- risk 0.60cvss 8.8epss 0.03
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
- risk 0.60cvss 8.8epss 0.02
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
- risk 0.60cvss 8.8epss 0.02
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
- risk 0.60cvss 8.8epss 0.02
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
- risk 0.60cvss 8.8epss 0.03
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
- risk 0.60cvss 8.8epss 0.02
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.
- risk 0.60cvss 8.8epss 0.02
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.
- risk 0.60cvss 8.8epss 0.03
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.