CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 27 of 188
- CVE-2016-8917HIGHCVSS 8.8EG 8.82017-03-31
IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.
- CVE-2016-8941HIGHCVSS 8.8EG 8.82017-02-01
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
- CVE-2016-9092HIGHCVSS 8.8EG 8.82017-05-11
The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social en…
- CVE-2016-9127HIGHCVSS 8.8EG 8.82017-03-28
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery ema…
- CVE-2016-9218HIGHCVSS 8.8EG 8.82017-01-26
A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releas…
- CVE-2016-9365HIGHCVSS 8.8EG 8.82017-02-13
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPo…
- CVE-2016-9455HIGHCVSS 8.8EG 8.82017-03-28
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/ba…
- CVE-2016-9456HIGHCVSS 8.8EG 8.82017-03-28
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabilities. Over 20+ suc…
- CVE-2016-9714HIGHCVSS 8.8EG 8.82017-07-31
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the we…
- CVE-2016-9716HIGHCVSS 8.8EG 8.82017-07-31
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website …
- CVE-2016-9730MEDIUMCVSS 4.3EG 4.32017-03-07
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.
- CVE-2016-9866CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x v…
- CVE-2016-9975HIGHCVSS 8.8EG 8.82017-02-24
IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 199…
- CVE-2016-9991HIGHCVSS 8.0EG 8.02017-06-08
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.
- CVE-2017-0045MEDIUMCVSS 5.5EG 5.52017-03-17
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker …
- CVE-2017-0362HIGHCVSS 8.8EG 8.82018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
- CVE-2017-0933HIGHCVSS 8.0EG 8.02018-03-22
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled pa…
- CVE-2017-1000008HIGHCVSS 8.8EG 8.82017-07-17
Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.
- CVE-2017-1000069HIGHCVSS 8.8EG 8.82017-07-17
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
- CVE-2017-1000085MEDIUMCVSS 6.5EG 6.52017-10-05
Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Ite…
- CVE-2017-1000090HIGHCVSS 8.8EG 8.82017-10-05
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the a…
- CVE-2017-1000091MEDIUMCVSS 6.3EG 6.32017-10-05
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, al…
- CVE-2017-1000092HIGHCVSS 7.5EG 7.52017-10-05
Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissi…
- CVE-2017-1000093HIGHCVSS 8.8EG 8.82017-10-05
Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does n…
- CVE-2017-1000147MEDIUMCVSS 6.8EG 6.82017-11-03
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a …
- CVE-2017-1000224MEDIUMCVSS 6.5EG 6.52017-11-17
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
- CVE-2017-1000244HIGHCVSS 8.8EG 8.82017-11-01
Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
- CVE-2017-1000356HIGHCVSS 8.8EG 8.82018-01-29
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrato…
- CVE-2017-1000432HIGHCVSS 8.0EG 8.02018-01-02
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
- CVE-2017-1000479HIGHCVSS 8.8EG 8.82018-01-03
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed i…
- CVE-2017-1000499HIGHCVSS 8.8EG 8.82018-01-03
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables…
- CVE-2017-1000504HIGHCVSS 8.1EG 8.12018-01-24
A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no lon…
- CVE-2017-10677HIGHCVSS 8.8EG 8.82017-08-06
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP.
- CVE-2017-10678HIGHCVSS 8.8EG 8.82017-06-29
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.
- CVE-2017-10680HIGHCVSS 8.8EG 8.82017-06-29
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.
- CVE-2017-10681HIGHCVSS 8.8EG 8.82017-06-29
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.
- CVE-2017-10961HIGHCVSS 8.8EG 8.82017-07-18
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
- CVE-2017-1097HIGHCVSS 8.8EG 8.82017-09-05
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website tr…
- CVE-2017-11193HIGHCVSS 8.8EG 8.82017-07-12
Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections ag…
- CVE-2017-11196HIGHCVSS 8.8EG 8.82017-07-12
Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.
- CVE-2017-11350HIGHCVSS 8.8EG 8.82017-09-13
Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on Axesstel MU553S MU55XS-V1.14 devices.
- CVE-2017-11455HIGHCVSS 8.8EG 8.82017-08-29
diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for…
- CVE-2017-11567HIGHCVSS 8.8EG 8.82017-09-07
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can …
- CVE-2017-11646HIGHCVSS 8.8EG 8.82017-07-28
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain any token that can mi…
- CVE-2017-11648HIGHCVSS 8.8EG 8.82017-07-31
Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnerability, as demonstrated by a goform/BasicSettings request to disable port filtering.
- CVE-2017-11649HIGHCVSS 8.8EG 8.82018-03-07
Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack the authentication of unspecified users for requests that enable SNMP on the remote devic…
- CVE-2017-11679HIGHCVSS 8.8EG 8.82017-07-27
Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action.
- CVE-2017-11680HIGHCVSS 8.8EG 8.82017-07-27
Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php.
- CVE-2017-11726HIGHCVSS 8.8EG 8.82017-07-31
services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by changing an e-mail address setting.
- CVE-2017-11876HIGHCVSS 8.8EG 8.82017-11-15
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on …
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →