Falhas do tipo CWE-352

6.050 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2021-24704Orange Form <= 1.0 - SQL Injection via CSRFEPSS 0.6%CVE-2022-47130MEDIUMA Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with adminEPSS 0.6%CVE-2022-1611Bulk Page Creator < 1.1.4 - Arbitrary Page Creation via CSRFEPSS 0.6%CVE-2022-1765Hot Linked Image Cacher <= 1.16 - Image upload/cache abuse via CSRFEPSS 0.6%CVE-2021-24328WP Login Security and History <= 1.0 - CSRF to Stored Cross-Site Scripting (XSS)EPSS 0.6%CVE-2021-4168MEDIUMCross-Site Request Forgery (CSRF) in star7th/showdocEPSS 0.6%CVE-2021-25010Post Snippets < 3.1.4 - CSRF to Stored Cross-Site ScriptingEPSS 0.6%CVE-2020-15156MEDIUMXSS due to lack of CSRF validation for replying/publishingEPSS 0.6%CVE-2021-36444HIGHCross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token gEPSS 0.6%CVE-2021-36443HIGHCross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification.EPSS 0.6%CVE-2021-24879SupportCandy < 2.2.7 - CSRF to Cross-Site ScriptingEPSS 0.6%CVE-2022-0770Translate WordPress with GTranslate < 2.9.9 - CSRF to Account TakeoverEPSS 0.6%CVE-2023-3977MEDIUMInisev Plugins (Various Versions) - Cross-Site Request Forgery on handle_installation functionEPSS 0.6%CVE-2021-32730MEDIUMNo CSRF protection on the password change formEPSS 0.6%CVE-2022-1672Insights from Google PageSpeed < 4.0.7 - Multiple CSRFEPSS 0.6%CVE-2024-48962HIGHApache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)EPSS 0.6%CVE-2021-43353HIGHCrisp Live Chat <= 0.31 Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.6%CVE-2025-26206CRITICALCross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html coEPSS 0.6%CVE-2022-0335A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge aliEPSS 0.6%CVE-2025-55147HIGHCSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and IvaEPSS 0.6%