CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,378 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 31 of 188
- CVE-2017-5489HIGHCVSS 8.8EG 8.82017-01-15
Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.
- CVE-2017-5492HIGHCVSS 8.8EG 8.82017-01-15
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-acce…
- CVE-2017-5528HIGHCVSS 8.8EG 8.82017-06-29
Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretic…
- CVE-2017-5633HIGHCVSS 8.0EG 8.02017-03-06
Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impac…
- CVE-2017-5657HIGHCVSS 8.0EG 8.02017-05-22
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary action…
- CVE-2017-5781HIGHCVSS 8.8EG 8.82018-02-15
A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.
- CVE-2017-5796HIGHCVSS 8.8EG 8.82018-02-15
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.
- CVE-2017-5874HIGHCVSS 8.8EG 8.82017-03-22
CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.
- CVE-2017-5891HIGHCVSS 8.8EG 8.82017-05-10
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF.
- CVE-2017-5943HIGHCVSS 8.8EG 8.82017-07-03
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens via a crafted URL.
- CVE-2017-5959CRITICALCVSS 9.8EG 9.82017-02-21
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
- CVE-2017-6002HIGHCVSS 8.8EG 8.82017-03-27
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
- CVE-2017-6038HIGHCVSS 7.1EG 7.12017-06-30
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the…
- CVE-2017-6042HIGHCVSS 8.8EG 8.82017-06-30
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by …
- CVE-2017-6066HIGHCVSS 8.8EG 8.82017-03-27
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
- CVE-2017-6068HIGHCVSS 8.8EG 8.82017-03-27
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
- CVE-2017-6069HIGHCVSS 8.8EG 8.82017-03-27
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
- CVE-2017-6080CRITICALCVSS 9.8EG 9.82017-03-13
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerability, an attacker can send cross-domain req…
- CVE-2017-6081HIGHCVSS 8.8EG 8.82017-03-13
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie.
- CVE-2017-6086HIGHCVSS 8.8EG 8.82017-06-27
Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to hijack the authentication of logged administrators to (1) add an administrator user via a c…
- CVE-2017-6127HIGHCVSS 8.8EG 8.82017-02-21
Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow remote attackers to hijack the authentication of administrators for requests that (1) chan…
- CVE-2017-6180HIGHCVSS 8.8EG 8.82017-03-13
Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages).
- CVE-2017-6328HIGHCVSS 8.8EG 8.82017-08-11
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized…
- CVE-2017-6366HIGHCVSS 8.8EG 8.82017-03-15
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name para…
- CVE-2017-6379HIGHCVSS 7.5EG 7.52017-03-16
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
- CVE-2017-6411HIGHCVSS 8.8EG 8.82017-03-06
Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.
- CVE-2017-6634HIGHCVSS 8.8EG 8.82017-05-22
A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected s…
- CVE-2017-6659HIGHCVSS 8.8EG 8.82017-06-13
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected…
- CVE-2017-6756HIGHCVSS 8.8EG 8.82017-08-07
A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of defense against cr…
- CVE-2017-6803HIGHCVSS 8.8EG 8.82017-03-20
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change t…
- CVE-2017-6819MEDIUMCVSS 6.5EG 6.52017-03-12
In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file t…
- CVE-2017-6914HIGHCVSS 7.1EG 7.12017-03-15
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted.
- CVE-2017-6915MEDIUMCVSS 4.3EG 4.32017-03-15
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be changed.
- CVE-2017-6916MEDIUMCVSS 4.3EG 4.32017-03-15
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
- CVE-2017-6917MEDIUMCVSS 4.3EG 4.32017-03-15
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page. The Colophon can be changed.
- CVE-2017-6918MEDIUMCVSS 4.3EG 4.32017-03-15
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
- CVE-2017-7178HIGHCVSS 8.8EG 8.82017-03-18
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and…
- CVE-2017-7398HIGHCVSS 8.8EG 8.82017-04-04
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrat…
- CVE-2017-7404HIGHCVSS 8.8EG 8.82017-07-07
On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send requests to the victim's Router without knowing the credential…
- CVE-2017-7423HIGHCVSS 8.8EG 8.82017-08-21
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to fo…
- CVE-2017-7431HIGHCVSS 8.8EG 8.82017-05-03
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
- CVE-2017-7446HIGHCVSS 8.8EG 8.82017-04-05
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
- CVE-2017-7447HIGHCVSS 8.8EG 8.82017-04-05
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
- CVE-2017-7491MEDIUMCVSS 4.3EG 4.32017-05-15
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
- CVE-2017-7556HIGHCVSS 8.8EG 8.82017-08-17
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.
- CVE-2017-7557HIGHCVSS 8.8EG 8.82017-08-22
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
- CVE-2017-7571HIGHCVSS 8.0EG 8.02017-04-06
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
- CVE-2017-7620MEDIUMCVSS 6.5EG 6.52017-05-21
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostn…
- CVE-2017-7635HIGHCVSS 8.8EG 8.82018-06-05
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
- CVE-2017-7641HIGHCVSS 8.8EG 8.82018-03-08
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →