Fallos del tipo CWE-352

6050 resultados

Falsificação de Requisição Entre Sites (CSRF)

A aplicação não valida se uma requisição legítima foi realmente iniciada pelo usuário autenticado, permitindo que um atacante force ações em nome da vítima. Um invasor engana o navegador do usuário a enviar requisições maliciosas para um site onde a vítima está logada, explorando a confiança automática do navegador.

Ejemplo

Um usuário logado em seu banco recebe um email com um link que, ao clicar, faz uma requisição invisível para transferir dinheiro. Como o navegador envia automaticamente os cookies de sessão do banco, a transferência é processada sem confirmação adicional do usuário.

Cómo mitigar

Implemente tokens CSRF únicos por sessão (validados em cada requisição POST/PUT/DELETE), use o padrão SameSite nos cookies, e exija confirmação do usuário para ações críticas. Frameworks modernos como Laravel, Django e Express têm proteção nativa — ative por padrão.

CVE-2024-0379MEDIUMCustom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options UpdateEPSS 1.0%CVE-2009-3022MEDIUMCross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other uEPSS 1.0%CVE-2016-10522rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens andEPSS 1.0%CVE-2017-12271A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on aEPSS 1.0%CVE-2019-16009HIGHCisco IOS and Cisco IOS XE Software Web UI Cross-Site Request Forgery VulnerabilityEPSS 1.0%CVE-2019-1904HIGHCisco IOS XE Software Web UI Cross-Site Request Forgery VulnerabilityEPSS 1.0%CVE-2020-15259HIGHCSRF in Auth0 ad-ldap-connectorEPSS 1.0%CVE-2021-32732HIGHCross-Site Request Forgery in xwiki-platformEPSS 1.0%CVE-2015-20105ClickBank Affiliate Ads <= 1.20 - CSRF to Stored Cross-Site ScriptingEPSS 1.0%CVE-2024-0624MEDIUMPaid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders UpdateEPSS 1.0%CVE-2024-22416CRITICALCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalationEPSS 0.9%CVE-2018-0365A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker tEPSS 0.9%CVE-2018-15445MEDIUMCisco Energy Management Suite Cross-Site Request Forgery VulnerabilityEPSS 0.9%CVE-2020-8282A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have bEPSS 0.9%CVE-2022-29429HIGHWordPress Code Snippets Extended plugin <= 1.4.7 - Cross-Site Request Forgery (CSRF) leading to Remote Code Execution (RCE) vulnerabilityEPSS 0.9%CVE-2020-7005In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an aEPSS 0.9%CVE-2021-21241HIGHCSRF can expose users authentication token in Flask-Security-TooEPSS 0.9%CVE-2021-24639OMGF < 4.5.4 - Subscriber+ Arbitrary File/Folder DeletionEPSS 0.9%CVE-2024-27448CRITICALMailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js EPSS 0.9%CVE-2024-0588MEDIUMPaid Memberships Pro <= 2.12.10 - Cross-Site Request ForgeryEPSS 0.9%