Fallos del tipo CWE-352

6072 resultados

Falsificação de Requisição Entre Sites (CSRF)

A aplicação não valida se uma requisição legítima foi realmente iniciada pelo usuário autenticado, permitindo que um atacante force ações em nome da vítima. Um invasor engana o navegador do usuário a enviar requisições maliciosas para um site onde a vítima está logada, explorando a confiança automática do navegador.

Ejemplo

Um usuário logado em seu banco recebe um email com um link que, ao clicar, faz uma requisição invisível para transferir dinheiro. Como o navegador envia automaticamente os cookies de sessão do banco, a transferência é processada sem confirmação adicional do usuário.

Cómo mitigar

Implemente tokens CSRF únicos por sessão (validados em cada requisição POST/PUT/DELETE), use o padrão SameSite nos cookies, e exija confirmação do usuário para ações críticas. Frameworks modernos como Laravel, Django e Express têm proteção nativa — ative por padrão.

CVE-2023-28172MEDIUMWordPress WP Google Map Plugin Plugin <= 4.4.2 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-30478MEDIUMWordPress Newsletters Plugin <= 4.8.8 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2022-2312—Student Result or Employee Database < 1.7.5 - Stored Cross Site Scripting via CSRFEPSS 0.3%CVE-2023-0735MEDIUMCross-Site Request Forgery (CSRF) in wallabag/wallabagEPSS 0.3%CVE-2023-26531MEDIUMWordPress 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 Plugin <= 4.2.7 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-34171MEDIUMWordPress WP Report Post Plugin <= 2.1.2 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-34025MEDIUMWordPress LWS Hide Login Plugin <= 2.1.6 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2024-47359MEDIUMWordPress Depicter plugin <= 3.2.2 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2023-36690HIGHWordPress WPLMS Theme < 4.900 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2026-32989HIGHPrecurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file uploadEPSS 0.3%CVE-2023-33314MEDIUMWordPress BEAR Plugin <= 1.1.3.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-32978MEDIUMA cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server usEPSS 0.3%CVE-2023-33003MEDIUMA cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to reset profiler statistiEPSS 0.3%CVE-2021-27759LOWThis vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was seEPSS 0.3%CVE-2017-5263—Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which areEPSS 0.3%CVE-2023-26535MEDIUMWordPress Sheets To WP Table Live Sync Plugin <= 2.12.15 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2024-12644HIGHChunghwa Telecom tbm-client - Arbitrary File Copy and PasteEPSS 0.3%CVE-2022-47177MEDIUMWordPress WP EasyPay Plugin <= 4.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-1807MEDIUMElementor Addons, Widgets and Enhancements – Stax <= 1.4.3 - Cross-Site Request Forgery via toggle_widgetEPSS 0.3%CVE-2022-47149MEDIUMWordPress Shortlinks by Pretty Links Plugin <= 3.4.0 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%