VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 8 of 479
  • CVE-2020-15046HigJun 24, 2020
    risk 0.60cvss 8.8epss 0.02

    The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.

  • CVE-2019-16068HigMar 19, 2020
    risk 0.60cvss 8.8epss 0.01

    A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site.

  • CVE-2012-2629HigFeb 20, 2020
    risk 0.60cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to…

  • CVE-2014-2225HigFeb 8, 2020
    risk 0.60cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified…

  • CVE-2014-5288HigFeb 7, 2020
    risk 0.60cvss 8.8epss 0.02

    A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.

  • CVE-2013-7053HigFeb 4, 2020
    risk 0.60cvss 8.8epss 0.03

    D-Link DIR-100 4.03B07: cli.cgi CSRF

  • CVE-2020-8424HigJan 28, 2020
    risk 0.60cvss 8.8epss 0.02

    Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.

  • CVE-2020-7991HigJan 26, 2020
    risk 0.60cvss 8.8epss 0.03

    Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.

  • CVE-2014-3136HigDec 27, 2019
    risk 0.60cvss 8.8epss 0.03

    Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors.

  • CVE-2015-3140HigNov 21, 2019
    risk 0.60cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567

  • CVE-2019-13529HigOct 9, 2019
    risk 0.60cvss 8.8epss 0.03

    An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a…

  • CVE-2019-14346HigAug 6, 2019
    risk 0.60cvss 8.8epss 0.03

    Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.

  • CVE-2019-14328HigJul 28, 2019
    risk 0.60cvss 8.8epss 0.03

    The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

  • CVE-2019-13961HigJul 18, 2019
    risk 0.60cvss 8.8epss 0.02

    A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.

  • CVE-2019-10847HigMay 24, 2019
    risk 0.60cvss 8.8epss 0.02

    Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.

  • CVE-2019-11569HigMay 6, 2019
    risk 0.60cvss 8.8epss 0.02

    Veeam ONE Reporter 9.5.0.3201 allows CSRF.

  • CVE-2019-6282HigMar 21, 2019
    risk 0.60cvss 8.8epss 0.03

    ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.

  • CVE-2018-14575HigMar 21, 2019
    risk 0.60cvss 8.8epss 0.02

    Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.

  • CVE-2019-9769HigMar 14, 2019
    risk 0.60cvss 8.8epss 0.02

    PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.

  • CVE-2019-6710HigMar 7, 2019
    risk 0.60cvss 8.8epss 0.03

    Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.