CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 28 of 188
- CVE-2017-1194HIGHCVSS 8.8EG 8.82017-04-28
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID…
- CVE-2017-12126HIGHCVSS 8.8EG 8.82018-05-14
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forgery. An attacker can create malicious HTML…
- CVE-2017-1218HIGHCVSS 8.8EG 8.82017-07-19
IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123858.
- CVE-2017-12253HIGHCVSS 8.8EG 8.82017-09-21
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exp…
- CVE-2017-12271HIGHCVSS 8.8EG 8.82017-10-19
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protecti…
- CVE-2017-12415HIGHCVSS 7.5EG 7.52018-02-20
OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (mai…
- CVE-2017-12439HIGHCVSS 7.5EG 7.52017-08-05
SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant co…
- CVE-2017-12584HIGHCVSS 8.8EG 8.82017-08-06
There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attack…
- CVE-2017-12589HIGHCVSS 8.8EG 8.82017-08-18
ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.
- CVE-2017-12593HIGHCVSS 8.8EG 8.82017-08-18
ASUS DSL-N10S V2.1.16_APAC devices allow CSRF.
- CVE-2017-12631HIGHCVSS 8.8EG 8.82017-11-30
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3 and Spring 4 plugins in versions…
- CVE-2017-12651HIGHCVSS 8.8EG 8.82017-08-07
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.
- CVE-2017-12703HIGHCVSS 8.8EG 8.82017-08-25
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verify whether a request was intentionally pr…
- CVE-2017-12789HIGHCVSS 8.8EG 8.82019-05-10
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in …
- CVE-2017-12790MEDIUMCVSS 6.5EG 6.52019-05-09
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.
- CVE-2017-12838HIGHCVSS 8.8EG 8.82017-09-07
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.
- CVE-2017-12853HIGHCVSS 8.8EG 8.82017-08-14
The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.
- CVE-2017-12881HIGHCVSS 8.8EG 8.82017-08-18
Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerabil…
- CVE-2017-12970HIGHCVSS 8.8EG 8.82017-08-23
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.
- CVE-2017-1300HIGHCVSS 8.8EG 8.82017-11-01
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162.
- CVE-2017-13129HIGHCVSS 8.0EG 8.02017-09-26
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.
- CVE-2017-14011HIGHCVSS 8.8EG 8.82017-10-17
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site request forgery. This may allow an attacker …
- CVE-2017-14048HIGHCVSS 8.8EG 8.82017-08-31
BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this can be exploited via CSRF.
- CVE-2017-14092HIGHCVSS 8.8EG 8.82017-12-16
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
- CVE-2017-14267HIGHCVSS 8.8EG 8.82017-09-11
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSetting, goform/setReset, and goform/uploadBackupSettings.
- CVE-2017-14362HIGHCVSS 7.3EG 7.32017-12-13
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack.
- CVE-2017-1442HIGHCVSS 8.8EG 8.82017-08-30
IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 128107.
- CVE-2017-14530HIGHCVSS 8.0EG 8.02017-09-18
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
- CVE-2017-14683HIGHCVSS 8.8EG 8.82017-09-25
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
- CVE-2017-14924HIGHCVSS 8.0EG 8.02017-09-30
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator op…
- CVE-2017-14925HIGHCVSS 8.0EG 8.02017-09-30
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a …
- CVE-2017-14956MEDIUMCVSS 5.7EG 5.72017-10-18
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the poss…
- CVE-2017-15063HIGHCVSS 8.8EG 8.82017-10-06
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack …
- CVE-2017-15084MEDIUMCVSS 6.5EG 6.52017-10-06
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
- CVE-2017-15296HIGHCVSS 8.8EG 8.82017-10-16
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
- CVE-2017-15516HIGHCVSS 8.8EG 8.82017-11-16
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated action in the user interface.
- CVE-2017-15608MEDIUMCVSS 6.5EG 6.52018-09-26
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
- CVE-2017-15645HIGHCVSS 8.8EG 8.82017-10-19
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
- CVE-2017-15729HIGHCVSS 8.8EG 8.82017-10-22
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.
- CVE-2017-15730HIGHCVSS 8.8EG 8.82017-10-22
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
- CVE-2017-15731HIGHCVSS 8.8EG 8.82017-10-22
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.
- CVE-2017-15732HIGHCVSS 8.8EG 8.82017-10-22
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.
- CVE-2017-15733HIGHCVSS 8.8EG 8.82017-10-22
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.
- CVE-2017-15734HIGHCVSS 8.8EG 8.82017-10-22
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
- CVE-2017-15735HIGHCVSS 8.8EG 8.82017-10-22
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
- CVE-2017-15808HIGHCVSS 8.8EG 8.82017-10-23
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
- CVE-2017-16244HIGHCVSS 8.8EG 8.82017-11-01
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection …
- CVE-2017-1631HIGHCVSS 8.8EG 8.82017-12-20
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Fo…
- CVE-2017-16563HIGHCVSS 8.0EG 8.02017-11-06
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.
- CVE-2017-16565HIGHCVSS 8.8EG 8.82017-11-06
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →