Falhas do tipo CWE-352

6.056 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2024-7760HIGHCSRF in aimhubio/aimEPSS 0.5%CVE-2025-1306HIGHNewscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File UploadEPSS 0.5%CVE-2026-14620MEDIUMwebpack-dev-server vulnerable to cross-site request forgery via internal developer endpointsEPSS 0.5%CVE-2021-41176MEDIUMlogout CSRF in Pterodactyl PanelEPSS 0.5%CVE-2024-1879HIGHCSRF to RCE in significant-gravitas/autogptEPSS 0.5%CVE-2022-2353MEDIUMCross-Site Request Forgery (CSRF) in microweber/microweberEPSS 0.5%CVE-2020-29030HIGHInsufficient CSRF guardsEPSS 0.5%CVE-2024-6316HIGHGenerate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File UploadEPSS 0.5%CVE-2022-2987HIGHLdap WP Login / Active Directory Integration < 3.0.2 - Unauthenticated Settings Update to Auth BypassEPSS 0.5%CVE-2016-9456Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admiEPSS 0.5%CVE-2020-11003MEDIUMCSRF and DNS Rebinding in OasisEPSS 0.5%CVE-2023-24447HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attaEPSS 0.5%CVE-2023-24452HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an atEPSS 0.5%CVE-2023-24432HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers to connect to an atEPSS 0.5%CVE-2023-24437HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers tEPSS 0.5%CVE-2024-45693HIGHApache CloudStack: Request origin validation bypass makes account takeover possibleEPSS 0.5%CVE-2020-14368A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, EPSS 0.5%CVE-2022-1576WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRFEPSS 0.5%CVE-2022-2091Cache Images < 3.2.1 - Image Upload / Import via CSRFEPSS 0.5%CVE-2022-2933MEDIUM0mk Shortener <= 0.2 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.5%