Falhas do tipo CWE-352

6.050 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2021-34634HIGHNifty Newsletters <= 4.0.23 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-34628HIGHAdmin Custom Login <= 3.2.7 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-34637HIGHPost Index <= 0.7.5 Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-1599Admin Management Xtended < 2.4.5 - Post Visibility/Date/Comment Status Update via CSRFEPSS 0.7%CVE-2021-24218Facebook for WordPress 3.0.0-3.0.3 - CSRF to Stored XSS and Settings DeletionEPSS 0.7%CVE-2019-1764HIGHCisco IP Phone 8800 Series Cross-Site Request Forgery VulnerabilityEPSS 0.7%CVE-2024-31988CRITICALXWiki Platform CSRF remote code execution through the realtime HTML Converter APIEPSS 0.7%CVE-2020-8168We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AiEPSS 0.7%CVE-2021-1227HIGHCisco NX-OS Software NX-API Cross-Site Request Forgery VulnerabilityEPSS 0.7%CVE-2021-24711Software License Manager < 4.5.1 - Arbitrary Domain Deletion via CSRFEPSS 0.7%CVE-2024-22939HIGHCross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_EPSS 0.7%CVE-2022-40623WAVLINK Quantum D4G (WN531G3) CSRFEPSS 0.7%CVE-2019-1722MEDIUMCisco Expressway Series and Cisco TelePresence Video Communication Server Cross-Site Request Forgery VulnerabilityEPSS 0.7%CVE-2018-0259A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cEPSS 0.7%CVE-2021-25073WP125 < 1.5.5 - Arbitrary Ad Deletion via CSRFEPSS 0.7%CVE-2017-7556Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their weEPSS 0.7%CVE-2024-27439MEDIUMApache Wicket: Possible bypass of CSRF protectionEPSS 0.7%CVE-2023-32991HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HEPSS 0.7%CVE-2021-34633HIGHYoutube Feeder <= 2.0.1 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-34632HIGHSEO Backlinks <= 4.0.1 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.7%