CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,732)
page 8 of 487| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-50858 | Hig | 0.60 | 8.8 | 0.02 | Jan 14, 2025 | Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration. | ||
| CVE-2024-50966 | Cri | 0.60 | 9.3 | 0.00 | Nov 8, 2024 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin. | ||
| CVE-2024-6244 | Hig | 0.60 | 8.8 | 0.03 | Jul 22, 2024 | The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | ||
| CVE-2023-48292 | Cri | 0.60 | 9.6 | 0.23 | Nov 20, 2023 | The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site request forgery vulnerability in the admin tool for executing shell commands on the server allows an attacker to execute… | ||
| CVE-2022-25241 | Hig | 0.60 | 8.8 | 0.03 | Feb 16, 2022 | In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). | ||
| CVE-2021-32403 | Hig | 0.60 | 8.8 | 0.02 | May 17, 2021 | Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules. | ||
| CVE-2021-30147 | Hig | 0.60 | 8.8 | 0.04 | Apr 7, 2021 | DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. | ||
| CVE-2021-27885 | Hig | 0.60 | 8.8 | 0.03 | Mar 2, 2021 | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. | ||
| CVE-2020-15046 | Hig | 0.60 | 8.8 | 0.02 | Jun 24, 2020 | The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88. | ||
| CVE-2019-16068 | Hig | 0.60 | 8.8 | 0.01 | Mar 19, 2020 | A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site. | ||
| CVE-2012-2629 | Hig | 0.60 | 8.8 | 0.02 | Feb 20, 2020 | Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to… | ||
| CVE-2014-2225 | Hig | 0.60 | 8.8 | 0.01 | Feb 8, 2020 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified… | ||
| CVE-2014-5288 | Hig | 0.60 | 8.8 | 0.02 | Feb 7, 2020 | A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages. | ||
| CVE-2013-7053 | Hig | 0.60 | 8.8 | 0.03 | Feb 4, 2020 | D-Link DIR-100 4.03B07: cli.cgi CSRF | ||
| CVE-2020-8424 | Hig | 0.60 | 8.8 | 0.02 | Jan 28, 2020 | Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php. | ||
| CVE-2020-7991 | Hig | 0.60 | 8.8 | 0.03 | Jan 26, 2020 | Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. | ||
| CVE-2014-3136 | Hig | 0.60 | 8.8 | 0.03 | Dec 27, 2019 | Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors. | ||
| CVE-2015-3140 | Hig | 0.60 | 8.8 | 0.01 | Nov 21, 2019 | Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567 | ||
| CVE-2019-13529 | Hig | 0.60 | 8.8 | 0.03 | Oct 9, 2019 | An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a… | ||
| CVE-2019-14346 | Hig | 0.60 | 8.8 | 0.03 | Aug 6, 2019 | Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password. |
- risk 0.60cvss 8.8epss 0.02
Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.
- risk 0.60cvss 9.3epss 0.00
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.
- risk 0.60cvss 8.8epss 0.03
The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- risk 0.60cvss 9.6epss 0.23
The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site request forgery vulnerability in the admin tool for executing shell commands on the server allows an attacker to execute…
- risk 0.60cvss 8.8epss 0.03
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
- risk 0.60cvss 8.8epss 0.02
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.
- risk 0.60cvss 8.8epss 0.04
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
- risk 0.60cvss 8.8epss 0.03
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
- risk 0.60cvss 8.8epss 0.02
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
- risk 0.60cvss 8.8epss 0.01
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site.
- risk 0.60cvss 8.8epss 0.02
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to…
- risk 0.60cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified…
- risk 0.60cvss 8.8epss 0.02
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
- risk 0.60cvss 8.8epss 0.03
D-Link DIR-100 4.03B07: cli.cgi CSRF
- risk 0.60cvss 8.8epss 0.02
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
- risk 0.60cvss 8.8epss 0.03
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
- risk 0.60cvss 8.8epss 0.03
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors.
- risk 0.60cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567
- risk 0.60cvss 8.8epss 0.03
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a…
- risk 0.60cvss 8.8epss 0.03
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.