VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 9 of 479
  • CVE-2019-9625HigMar 7, 2019
    risk 0.60cvss 8.8epss 0.02

    JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

  • CVE-2019-6249HigJan 13, 2019
    risk 0.60cvss 8.8epss 0.03

    An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.

  • CVE-2018-18773HigNov 20, 2018
    risk 0.60cvss 8.8epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

  • CVE-2018-18772HigNov 20, 2018
    risk 0.60cvss 8.8epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.

  • CVE-2018-18799HigNov 16, 2018
    risk 0.60cvss 8.8epss 0.02

    School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.

  • CVE-2018-18797HigNov 16, 2018
    risk 0.60cvss 8.8epss 0.02

    School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.

  • CVE-2018-18794HigNov 16, 2018
    risk 0.60cvss 8.8epss 0.02

    School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.

  • CVE-2018-19135HigNov 11, 2018
    risk 0.60cvss 8.8epss 0.03

    ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by…

  • CVE-2018-19138HigNov 9, 2018
    risk 0.60cvss 8.8epss 0.02

    WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.

  • CVE-2018-15884HigAug 28, 2018
    risk 0.60cvss 8.8epss 0.03

    RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.

  • CVE-2018-15845HigAug 25, 2018
    risk 0.60cvss 8.8epss 0.02

    There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.

  • CVE-2018-15844HigAug 25, 2018
    risk 0.60cvss 8.8epss 0.02

    An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.

  • CVE-2018-14029HigJul 13, 2018
    risk 0.60cvss 8.8epss 0.03

    CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field.

  • CVE-2018-13989HigJul 11, 2018
    risk 0.60cvss 8.8epss 0.03

    Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device.

  • CVE-2018-12739HigJul 5, 2018
    risk 0.60cvss 8.8epss 0.02

    In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.

  • CVE-2018-13032HigJul 1, 2018
    risk 0.60cvss 8.8epss 0.02

    ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.

  • CVE-2018-12603HigJun 25, 2018
    risk 0.60cvss 8.8epss 0.04

    Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.

  • CVE-2018-12602HigJun 25, 2018
    risk 0.60cvss 8.8epss 0.03

    A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.

  • CVE-2018-6563HigJun 20, 2018
    risk 0.60cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by…

  • CVE-2018-12114HigJun 14, 2018
    risk 0.60cvss 8.8epss 0.03

    Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.