CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,376 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 15 of 188
- CVE-2013-5672MEDIUMCVSS v2 6.8EG 6.82013-09-10
Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add a testimonial via an iNIC_testi…
- CVE-2013-5696MEDIUMCVSS v2 6.8EG 6.82013-09-23
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a …
- CVE-2013-5708MEDIUMCVSS v2 6.8EG 6.82013-09-06
Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vuln…
- CVE-2013-5726MEDIUMCVSS v2 6.8EG 6.82013-11-12
Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the…
- CVE-2013-5730MEDIUMCVSS v2 6.8EG 6.82013-11-20
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the authentication of administrators for requests that (1) enable or disable Wireless MAC Address…
- CVE-2013-5748MEDIUMCVSS v2 6.8EG 6.82014-05-12
Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hijack the authentication of users for requests that add projects via an add_project action.
- CVE-2013-5937MEDIUMCVSS v2 6.8EG 6.82013-09-25
Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving th…
- CVE-2013-5954MEDIUMCVSS v2 6.8EG 6.82014-04-25
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertise…
- CVE-2013-5977MEDIUMCVSS v2 6.8EG 6.82013-11-01
Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify prod…
- CVE-2013-5993MEDIUMCVSS v2 6.8EG 6.82013-11-21
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors related to refusals.
- CVE-2013-6018MEDIUMCVSS v2 6.8EG 6.82013-10-28
Cross-site request forgery (CSRF) vulnerability in login.jsp in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to hijack the authentication of arbitrary users for requests that change a password.
- CVE-2013-6028MEDIUMCVSS v2 6.8EG 6.82014-01-12
Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts, (2) modify user accounts, (3) del…
- CVE-2013-6166MEDIUMCVSS v2 6.8EG 6.82014-02-15
Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted par…
- CVE-2013-6167MEDIUMCVSS v2 6.8EG 6.82014-02-15
Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted …
- CVE-2013-6173MEDIUMCVSS v2 6.8EG 6.82013-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Ente…
- CVE-2013-6188MEDIUMCVSS v2 6.8EG 6.82014-03-14
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2013-6192MEDIUMCVSS v2 6.8EG 6.82013-12-17
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2013-6202MEDIUMCVSS v2 6.8EG 6.82014-02-24
Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote attackers to hijack the authentication of unspecified victims for requests that (1) insert XSS sequences or (2) execut…
- CVE-2013-6275MEDIUMCVSS 6.5EG 6.52019-11-05
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
- CVE-2013-6346MEDIUMCVSS v2 6.8EG 6.82013-11-02
Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2013-6357MEDIUMCVSS v2 6.8EG 6.82013-11-13
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via t…
- CVE-2013-6364HIGHCVSS 8.8EG 8.82019-11-05
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
- CVE-2013-6365MEDIUMCVSS 5.3EG 5.32019-11-05
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
- CVE-2013-6443MEDIUMCVSS v2 6.8EG 6.82014-01-23
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
- CVE-2013-6710MEDIUMCVSS v2 6.8EG 6.82013-12-14
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCul25567.
- CVE-2013-6797MEDIUMCVSS v2 6.8EG 6.82013-11-19
Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that embed…
- CVE-2013-6811HIGHCVSS 8.8EG 8.82019-11-22
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote …
- CVE-2013-6826MEDIUMCVSS v2 6.8EG 6.82013-11-20
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.
- CVE-2013-6852MEDIUMCVSS v2 6.8EG 6.82013-11-22
Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administrators for requests that change an administrative password via the setPassword method.
- CVE-2013-6883MEDIUMCVSS v2 6.8EG 6.82013-12-17
Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administrators for requests that modify the disk erase technique set…
- CVE-2013-6922MEDIUMCVSS v2 6.8EG 6.82014-01-21
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accoun…
- CVE-2013-6942MEDIUMCVSS v2 6.8EG 6.82014-03-11
Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the authentication of unsp…
- CVE-2013-6976MEDIUMCVSS v2 6.8EG 6.82013-12-19
Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication of administrators for requests that change a password via the Password and PasswordReEnter …
- CVE-2013-6992MEDIUMCVSS v2 6.8EG 6.82014-01-03
Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that…
- CVE-2013-7043HIGHCVSS v2 8.3EG 8.32013-12-10
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a p…
- CVE-2013-7053HIGHCVSS 8.8EG 8.82020-02-04
D-Link DIR-100 4.03B07: cli.cgi CSRF
- CVE-2013-7057MEDIUMCVSS v2 6.8EG 6.82014-11-04
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1…
- CVE-2013-7107MEDIUMCVSS v2 6.8EG 6.82014-01-15
Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypas…
- CVE-2013-7204MEDIUMCVSS v2 6.8EG 6.82014-01-17
Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users.
- CVE-2013-7209MEDIUMCVSS v2 6.8EG 6.82013-12-30
Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authentication of administrators for requests that change the user group permissions of arbitrary use…
- CVE-2013-7233MEDIUMCVSS v2 6.8EG 6.82013-12-30
Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move com…
- CVE-2013-7251MEDIUMCVSS v2 6.8EG 6.82014-01-02
Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) web/admin/, (2) web/core/, (3) web/dialog/, (4) web/fib…
- CVE-2013-7256MEDIUMCVSS v2 6.8EG 6.82014-01-03
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2013-7320MEDIUMCVSS v2 6.8EG 6.82014-02-06
Cross-site request forgery (CSRF) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to hijack the authentication of administrators for requests that modify configuration settings via …
- CVE-2013-7334MEDIUMCVSS v2 6.8EG 6.82014-03-11
Cross-site request forgery (CSRF) vulnerability in ImageCMS before 4.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the q parameter, related to CVE-2012-6290.
- CVE-2013-7346MEDIUMCVSS v2 6.8EG 6.82014-03-27
Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the sort parameter to system/authors/, …
- CVE-2013-7352MEDIUMCVSS v2 6.8EG 6.82014-04-02
Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] p…
- CVE-2013-7376MEDIUMCVSS v2 6.8EG 6.82014-05-14
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the authentication of administrators, as demonstrated by requests that conduct directory traversal…
- CVE-2013-7407MEDIUMCVSS v2 6.8EG 6.82014-10-22
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2013-7464HIGHCVSS 8.8EG 8.82018-08-08
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →