CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 9 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9625 | Hig | 0.60 | 8.8 | 0.02 | Mar 7, 2019 | JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. | ||
| CVE-2019-6249 | Hig | 0.60 | 8.8 | 0.03 | Jan 13, 2019 | An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add. | ||
| CVE-2018-18773 | Hig | 0.60 | 8.8 | 0.03 | Nov 20, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password. | ||
| CVE-2018-18772 | Hig | 0.60 | 8.8 | 0.03 | Nov 20, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command. | ||
| CVE-2018-18799 | Hig | 0.60 | 8.8 | 0.02 | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. | ||
| CVE-2018-18797 | Hig | 0.60 | 8.8 | 0.02 | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. | ||
| CVE-2018-18794 | Hig | 0.60 | 8.8 | 0.02 | Nov 16, 2018 | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. | ||
| CVE-2018-19135 | Hig | 0.60 | 8.8 | 0.03 | Nov 11, 2018 | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by… | ||
| CVE-2018-19138 | Hig | 0.60 | 8.8 | 0.02 | Nov 9, 2018 | WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI. | ||
| CVE-2018-15884 | Hig | 0.60 | 8.8 | 0.03 | Aug 28, 2018 | RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. | ||
| CVE-2018-15845 | Hig | 0.60 | 8.8 | 0.02 | Aug 25, 2018 | There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. | ||
| CVE-2018-15844 | Hig | 0.60 | 8.8 | 0.02 | Aug 25, 2018 | An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit. | ||
| CVE-2018-14029 | Hig | 0.60 | 8.8 | 0.03 | Jul 13, 2018 | CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field. | ||
| CVE-2018-13989 | Hig | 0.60 | 8.8 | 0.03 | Jul 11, 2018 | Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device. | ||
| CVE-2018-12739 | Hig | 0.60 | 8.8 | 0.02 | Jul 5, 2018 | In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266. | ||
| CVE-2018-13032 | Hig | 0.60 | 8.8 | 0.02 | Jul 1, 2018 | ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI. | ||
| CVE-2018-12603 | Hig | 0.60 | 8.8 | 0.04 | Jun 25, 2018 | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114. | ||
| CVE-2018-12602 | Hig | 0.60 | 8.8 | 0.03 | Jun 25, 2018 | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. | ||
| CVE-2018-6563 | Hig | 0.60 | 8.8 | 0.02 | Jun 20, 2018 | Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by… | ||
| CVE-2018-12114 | Hig | 0.60 | 8.8 | 0.03 | Jun 14, 2018 | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. |
- risk 0.60cvss 8.8epss 0.02
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
- risk 0.60cvss 8.8epss 0.03
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.
- risk 0.60cvss 8.8epss 0.03
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.
- risk 0.60cvss 8.8epss 0.03
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.
- risk 0.60cvss 8.8epss 0.02
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
- risk 0.60cvss 8.8epss 0.02
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
- risk 0.60cvss 8.8epss 0.02
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
- risk 0.60cvss 8.8epss 0.03
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by…
- risk 0.60cvss 8.8epss 0.02
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.
- risk 0.60cvss 8.8epss 0.03
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
- risk 0.60cvss 8.8epss 0.02
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
- risk 0.60cvss 8.8epss 0.02
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.
- risk 0.60cvss 8.8epss 0.03
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field.
- risk 0.60cvss 8.8epss 0.03
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device.
- risk 0.60cvss 8.8epss 0.02
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
- risk 0.60cvss 8.8epss 0.02
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.
- risk 0.60cvss 8.8epss 0.04
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.
- risk 0.60cvss 8.8epss 0.03
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
- risk 0.60cvss 8.8epss 0.02
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by…
- risk 0.60cvss 8.8epss 0.03
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.