Falhas do tipo CWE-352

6.050 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2024-34069HIGHWerkzeug's improper usage of a pathname and improper CSRF protection results in the remote command executionEPSS 3.4%CVE-2021-24174Database Backups <= 1.2.2.6 - CSRF to Backup DownloadEPSS 3.2%CVE-2019-13529HIGHAn attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissioEPSS 3.1%CVE-2020-13569HIGHA cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f6EPSS 3.0%CVE-2021-25052Button Generator < 2.3.3 - RFI leading to RCE via CSRFEPSS 3.0%CVE-2021-26296Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFacesEPSS 2.9%CVE-2005-1674MEDIUMCross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a liEPSS 2.9%CVE-2024-13913HIGHInstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.83 - Cross-Site Request Forgery to Local File InclusionEPSS 2.7%CVE-2022-4944MEDIUMkalcaddle KodExplorer cross-site request forgeryEPSS 2.7%CVE-2021-34620HIGHCSRF in WP Fluent Forms < 3.6.67 allows stored XSS and Privilege EscalationEPSS 2.6%CVE-2017-5264Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativEPSS 2.6%CVE-2018-16854MEDIUMA flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by EPSS 2.5%CVE-2020-5397MEDIUMCSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFluxEPSS 2.4%CVE-2022-21703MEDIUMCross Site Request Forgery in GrafanaEPSS 2.3%CVE-2020-10890HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interacEPSS 2.2%CVE-2020-10892HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interacEPSS 2.2%CVE-2018-12540In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form pEPSS 2.1%CVE-2022-41413MEDIUMperfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted iEPSS 2.0%CVE-2022-0088LOWCross-Site Request Forgery (CSRF) in yourls/yourlsEPSS 2.0%CVE-2018-4066An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A EPSS 1.9%