Weaknesses of type CWE-352

6,050 results

Falta de verificação de intenção do usuário (CSRF)

A aplicação não consegue confirmar se uma requisição legítima e bem-formada foi realmente intencionada pelo usuário que a enviou. Um atacante pode forjar requisições em nome de um usuário autenticado, fazendo-o executar ações sem consentimento. Isso ocorre porque a aplicação confia apenas em cookies de sessão, sem validar a origem ou intenção real da ação.

Example

Um usuário logado em seu banco acessa um site malicioso enquanto a sessão está ativa. O site injeta uma requisição silenciosa transferindo dinheiro da conta do usuário. Como o navegador envia automaticamente os cookies da sessão, a requisição é aceita como legítima pela aplicação do banco.

How to mitigate

Implemente tokens CSRF únicos e vinculados à sessão em formulários e requisições críticas (POST, PUT, DELETE). Valide a origem da requisição via verificação de header Referer/Origin e use o padrão SameSite nos cookies de sessão. Exija reautenticação para operações sensíveis.

CVE-2018-0255A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker toEPSS 0.9%CVE-2018-10884HIGHAnsible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker cEPSS 0.9%CVE-2016-7067MEDIUMMonit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disableEPSS 0.9%CVE-2025-49555HIGHAdobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)EPSS 0.9%CVE-2018-8844Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a weEPSS 0.9%CVE-2018-0363A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could alEPSS 0.9%CVE-2016-6578CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)EPSS 0.9%CVE-2017-9641PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that useEPSS 0.9%CVE-2019-3809MEDIUMA flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of EPSS 0.9%CVE-2023-35141HIGHIn Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the UEPSS 0.9%CVE-2024-20252CRITICALMultiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, EPSS 0.8%CVE-2016-6557The ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, is vulnerable to cross-site request forgeryEPSS 0.8%CVE-2018-0215A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.8%CVE-2022-1969HIGHMobile browser color select <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.8%CVE-2021-1257HIGHCisco DNA Center Cross-Site Request Forgery VulnerabilityEPSS 0.8%CVE-2018-0216A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.8%CVE-2014-0594HIGHCSRF protection incorrectly disabledEPSS 0.8%CVE-2018-0107A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unwanted actiEPSS 0.8%CVE-2018-0148A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) SupervEPSS 0.8%CVE-2017-6756A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, reEPSS 0.8%