CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,732)
page 9 of 487| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14328 | Hig | 0.60 | 8.8 | 0.03 | Jul 28, 2019 | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | ||
| CVE-2019-13961 | Hig | 0.60 | 8.8 | 0.02 | Jul 18, 2019 | A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php. | ||
| CVE-2019-10847 | Hig | 0.60 | 8.8 | 0.02 | May 24, 2019 | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. | ||
| CVE-2019-11569 | Hig | 0.60 | 8.8 | 0.02 | May 6, 2019 | Veeam ONE Reporter 9.5.0.3201 allows CSRF. | ||
| CVE-2019-6282 | Hig | 0.60 | 8.8 | 0.03 | Mar 21, 2019 | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password. | ||
| CVE-2018-14575 | Hig | 0.60 | 8.8 | 0.02 | Mar 21, 2019 | Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject. | ||
| CVE-2019-9769 | Hig | 0.60 | 8.8 | 0.02 | Mar 14, 2019 | PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator. | ||
| CVE-2019-6710 | Hig | 0.60 | 8.8 | 0.03 | Mar 7, 2019 | Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. | ||
| CVE-2019-9625 | Hig | 0.60 | 8.8 | 0.02 | Mar 7, 2019 | JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. | ||
| CVE-2019-6249 | Hig | 0.60 | 8.8 | 0.03 | Jan 13, 2019 | An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add. | ||
| CVE-2018-18773 | Hig | 0.60 | 8.8 | 0.03 | Nov 20, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password. | ||
| CVE-2018-18772 | Hig | 0.60 | 8.8 | 0.03 | Nov 20, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command. | ||
| CVE-2018-18799 | Hig | 0.60 | 8.8 | 0.02 | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. | ||
| CVE-2018-18797 | Hig | 0.60 | 8.8 | 0.02 | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. | ||
| CVE-2018-18794 | Hig | 0.60 | 8.8 | 0.02 | Nov 16, 2018 | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. | ||
| CVE-2018-19135 | Hig | 0.60 | 8.8 | 0.03 | Nov 11, 2018 | ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by… | ||
| CVE-2018-19138 | Hig | 0.60 | 8.8 | 0.02 | Nov 9, 2018 | WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI. | ||
| CVE-2018-15884 | Hig | 0.60 | 8.8 | 0.03 | Aug 28, 2018 | RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter. | ||
| CVE-2018-15845 | Hig | 0.60 | 8.8 | 0.02 | Aug 25, 2018 | There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. | ||
| CVE-2018-15844 | Hig | 0.60 | 8.8 | 0.02 | Aug 25, 2018 | An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit. |
- risk 0.60cvss 8.8epss 0.03
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
- risk 0.60cvss 8.8epss 0.02
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
- risk 0.60cvss 8.8epss 0.02
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
- risk 0.60cvss 8.8epss 0.02
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
- risk 0.60cvss 8.8epss 0.03
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
- risk 0.60cvss 8.8epss 0.02
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.
- risk 0.60cvss 8.8epss 0.02
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.
- risk 0.60cvss 8.8epss 0.03
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
- risk 0.60cvss 8.8epss 0.02
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
- risk 0.60cvss 8.8epss 0.03
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.
- risk 0.60cvss 8.8epss 0.03
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.
- risk 0.60cvss 8.8epss 0.03
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.
- risk 0.60cvss 8.8epss 0.02
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
- risk 0.60cvss 8.8epss 0.02
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
- risk 0.60cvss 8.8epss 0.02
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
- risk 0.60cvss 8.8epss 0.03
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by…
- risk 0.60cvss 8.8epss 0.02
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.
- risk 0.60cvss 8.8epss 0.03
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
- risk 0.60cvss 8.8epss 0.02
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
- risk 0.60cvss 8.8epss 0.02
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.