CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,378 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 32 of 188
- CVE-2017-7661HIGHCVSS 8.8EG 8.82017-05-16
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in …
- CVE-2017-7662HIGHCVSS 8.8EG 8.82017-05-16
Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc. A CSRF (Cross Style Request Forgery) style vulnerabili…
- CVE-2017-7666HIGHCVSS 8.8EG 8.82017-07-17
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
- CVE-2017-7851HIGHCVSS 8.8EG 8.82017-11-15
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.
- CVE-2017-7852HIGHCVSS 8.8EG 8.82017-04-24
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element…
- CVE-2017-7877HIGHCVSS 8.8EG 8.82017-04-14
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
- CVE-2017-7881HIGHCVSS 8.8EG 8.82017-04-15
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in …
- CVE-2017-7906HIGHCVSS 8.8EG 8.82018-06-06
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.
- CVE-2017-7917HIGHCVSS 8.8EG 8.82017-05-29
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 1105131…
- CVE-2017-7926HIGHCVSS 8.8EG 8.82017-08-25
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur when an otherwise-unauthorized cross-site request is sent f…
- CVE-2017-7951HIGHCVSS 8.8EG 8.82017-04-21
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
- CVE-2017-7969HIGHCVSS 8.8EG 8.82017-09-26
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for mul…
- CVE-2017-7990HIGHCVSS 8.8EG 8.82017-04-21
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
- CVE-2017-8082MEDIUMCVSS 6.5EG 6.52017-04-24
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imag…
- CVE-2017-8098MEDIUMCVSS 6.5EG 6.52017-04-24
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.
- CVE-2017-8099HIGHCVSS 8.1EG 8.12017-04-24
There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.
- CVE-2017-8100MEDIUMCVSS 6.5EG 6.52017-04-24
There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.
- CVE-2017-8101HIGHCVSS 8.8EG 8.82017-04-24
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.
- CVE-2017-8138HIGHCVSS 8.8EG 8.82017-11-22
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal s…
- CVE-2017-8328HIGHCVSS 8.8EG 8.82019-06-18
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the …
- CVE-2017-8334HIGHCVSS 8.0EG 8.02019-06-18
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does n…
- CVE-2017-8382MEDIUMCVSS 4.5EG 4.52017-05-16
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.
- CVE-2017-8406HIGHCVSS 8.8EG 8.82019-07-02
An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the device's webserver and…
- CVE-2017-8407HIGHCVSS 8.8EG 8.82019-07-02
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request…
- CVE-2017-8836HIGHCVSS 8.8EG 8.82017-06-05
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attac…
- CVE-2017-8848MEDIUMCVSS 6.5EG 6.52017-05-08
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
- CVE-2017-8874HIGHCVSS 8.8EG 8.82017-05-10
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts.
- CVE-2017-8875MEDIUMCVSS 6.5EG 6.52017-05-10
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
- CVE-2017-8928HIGHCVSS 8.8EG 8.82017-05-14
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
- CVE-2017-8930HIGHCVSS 8.8EG 8.82017-05-14
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the en…
- CVE-2017-9033HIGHCVSS 8.8EG 8.82017-05-26
Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authentication of users for requests to start an update from an arbitrary source via a crafted …
- CVE-2017-9062HIGHCVSS 8.6EG 8.62017-05-18
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
- CVE-2017-9064HIGHCVSS 8.8EG 8.82017-05-18
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
- CVE-2017-9365HIGHCVSS 8.8EG 8.82017-06-02
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.
- CVE-2017-9379HIGHCVSS 8.8EG 8.82017-06-02
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to core\admin\modules\dashboard\vitals-statistics\404\create-301.ph…
- CVE-2017-9381HIGHCVSS 8.8EG 8.82019-06-17
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deleting apps on the device using the web management interface. It seems that the device does not…
- CVE-2017-9413HIGHCVSS 8.8EG 8.82017-07-25
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastR…
- CVE-2017-9414HIGHCVSS 8.8EG 8.82018-02-05
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks …
- CVE-2017-9415HIGHCVSS 7.5EG 7.52017-07-21
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted request to userSettings.…
- CVE-2017-9444HIGHCVSS 8.8EG 8.82017-06-05
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ig…
- CVE-2017-9489HIGHCVSS 8.8EG 8.82017-07-31
The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.
- CVE-2017-9490HIGHCVSS 8.8EG 8.82017-07-31
The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configuration changes via CSRF.
- CVE-2017-9517HIGHCVSS 8.8EG 8.82017-06-08
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
- CVE-2017-9518HIGHCVSS 8.8EG 8.82017-06-08
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
- CVE-2017-9519HIGHCVSS 8.8EG 8.82017-06-08
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
- CVE-2017-9641HIGHCVSS 8.8EG 8.82018-05-25
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater to mitigate this vulnerability.
- CVE-2017-9673HIGHCVSS 8.8EG 8.82017-06-15
In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), including its password.
- CVE-2017-9810HIGHCVSS 8.8EG 8.82017-07-17
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when …
- CVE-2017-9863HIGHCVSS 8.8EG 8.82017-08-05
An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a P…
- CVE-2017-9930HIGHCVSS 8.8EG 8.82017-07-21
Cross-Site Request Forgery (CSRF) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by a request to ajax.cgi that enables UPnP.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →