Fallos del tipo CWE-352

6056 resultados

Falsificação de Requisição Entre Sites (CSRF)

A aplicação não valida se uma requisição legítima foi realmente iniciada pelo usuário autenticado, permitindo que um atacante force ações em nome da vítima. Um invasor engana o navegador do usuário a enviar requisições maliciosas para um site onde a vítima está logada, explorando a confiança automática do navegador.

Ejemplo

Um usuário logado em seu banco recebe um email com um link que, ao clicar, faz uma requisição invisível para transferir dinheiro. Como o navegador envia automaticamente os cookies de sessão do banco, a transferência é processada sem confirmação adicional do usuário.

Cómo mitigar

Implemente tokens CSRF únicos por sessão (validados em cada requisição POST/PUT/DELETE), use o padrão SameSite nos cookies, e exija confirmação do usuário para ações críticas. Frameworks modernos como Laravel, Django e Express têm proteção nativa — ative por padrão.

CVE-2021-24823—Support Board < 3.3.6 - Arbitrary File Deletion via CSRFEPSS 0.5%CVE-2019-1632MEDIUMCisco Integrated Management Controller Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2020-6776HIGHCSRF in Bosch PRAESIDEO and Bosch PRAESENSA Management InterfaceEPSS 0.5%CVE-2022-41925LOWTailscale daemon is vulnerable to information disclosure via CSRFEPSS 0.5%CVE-2022-35228—SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricteEPSS 0.5%CVE-2024-31986CRITICALXWiki Platform CSRF remote code execution through scheduler job's document referenceEPSS 0.5%CVE-2021-24852—MouseWheel Smooth Scroll < 5.7 - Plugin's Setting Update via CSRFEPSS 0.5%CVE-2021-24802—Colorful Categories < 2.0.15 - Arbitrary Colors Update via CSRFEPSS 0.5%CVE-2021-24767—Redirect 404 Error Page to Homepage or Custom Page with Logs < 1.7.9 - Log Deletion via CSRFEPSS 0.5%CVE-2021-24766—404 to 301 < 3.0.9 - Logs Deletion via CSRFEPSS 0.5%CVE-2019-10176MEDIUMA flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component weEPSS 0.5%CVE-2021-24674—Genie WP Favicon <= 0.5.2 - Arbitrary Favicon Change via CSRFEPSS 0.5%CVE-2023-0088HIGHSwifty Page Manager <= 3.0.1 - Cross-Site Request ForgeryEPSS 0.5%CVE-2022-2518HIGHStockists Manager for Woocommerce <= 1.0.2.1 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.5%CVE-2021-4164HIGHCross-Site Request Forgery (CSRF) in janeczku/calibre-webEPSS 0.5%CVE-2021-3858MEDIUMCross-Site Request Forgery (CSRF) in snipe/snipe-itEPSS 0.5%CVE-2021-22954—A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other usersEPSS 0.5%CVE-2022-41227HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attEPSS 0.5%CVE-2021-36886MEDIUMWordPress Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.5.9 - Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.5%CVE-2022-0830—FormBuilder <= 1.08 - Stored Cross-Site Scripting via CSRFEPSS 0.5%