Fallos del tipo CWE-352

6058 resultados

Falsificação de Requisição Entre Sites (CSRF)

A aplicação não valida se uma requisição legítima foi realmente iniciada pelo usuário autenticado, permitindo que um atacante force ações em nome da vítima. Um invasor engana o navegador do usuário a enviar requisições maliciosas para um site onde a vítima está logada, explorando a confiança automática do navegador.

Ejemplo

Um usuário logado em seu banco recebe um email com um link que, ao clicar, faz uma requisição invisível para transferir dinheiro. Como o navegador envia automaticamente os cookies de sessão do banco, a transferência é processada sem confirmação adicional do usuário.

Cómo mitigar

Implemente tokens CSRF únicos por sessão (validados em cada requisição POST/PUT/DELETE), use o padrão SameSite nos cookies, e exija confirmação do usuário para ações críticas. Frameworks modernos como Laravel, Django e Express têm proteção nativa — ative por padrão.

CVE-2022-3119HIGHOAuth client Single Sign On for WordPress < 3.0.4 - Unauthenticated Settings Update to Authentication BypassEPSS 0.4%CVE-2021-4015MEDIUMCross-Site Request Forgery (CSRF) in firefly-iii/firefly-iiiEPSS 0.4%CVE-2021-36877MEDIUMWordPress uListing plugin <= 2.0.5 - Modify User Roles via Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2017-6038—A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The webEPSS 0.4%CVE-2022-46688MEDIUMA cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have JenkEPSS 0.4%CVE-2024-6309HIGHAttachment File Icons (AF Icons) <= 1.3 - Cross-Site Request Forgery to Arbitrary File UploadEPSS 0.4%CVE-2021-22950—Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for dEPSS 0.4%CVE-2019-3864MEDIUMA vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameteEPSS 0.4%CVE-2020-36745MEDIUMWP Project Manager <= 2.4.0 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2022-43418MEDIUMA cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-spEPSS 0.4%CVE-2021-4030HIGHA cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitraryEPSS 0.4%CVE-2022-0245MEDIUMCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchatEPSS 0.4%CVE-2020-19803HIGHCross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the backgroundEPSS 0.4%CVE-2021-36850MEDIUMWordPress Media File Renamer – Auto & Manual Rename plugin <= 5.1.9 - Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2025-47204MEDIUMAn issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitEPSS 0.4%CVE-2021-36878MEDIUMWordPress uListing plugin <= 2.0.5 - Settings Update via Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2023-4868MEDIUMSourceCodester Contact Manager App add.php cross-site request forgeryEPSS 0.4%CVE-2024-6320HIGHScrollTo Top <= 1.2.2 - Cross-Site Request Forgery to Arbitrary File UploadEPSS 0.4%CVE-2022-41236HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to repEPSS 0.4%CVE-2022-2260—GiveWP < 2.21.3 - DoS via CSRFEPSS 0.4%