Falhas do tipo CWE-352

6.057 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2022-3852HIGHVR Calendar <= 2.3.3 - Cross-Site Request ForgeryEPSS 0.5%CVE-2020-3124MEDIUMCisco Hosted Collaboration Mediation Fulfillment Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2018-15401Cisco Hosted Collaboration Mediation Fulfillment Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2020-3148HIGHCisco Prime Network Registrar Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2020-3261HIGHCisco Mobility Express Software Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2024-25982MEDIUMMsa-24-0005: csrf risk in language import utilityEPSS 0.5%CVE-2022-41996HIGHWordPress Avada premium theme <= 7.8.1 - Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.5%CVE-2024-57523MEDIUMCross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthoEPSS 0.5%CVE-2022-3274HIGHCross-Site Request Forgery (CSRF) on user's settings in GitHub repository ikus060/rdiffweb prior to 2.4.6. in ikus060/rdiffwebEPSS 0.5%CVE-2020-19278HIGHCross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/EPSS 0.5%CVE-2024-44677CRITICALeladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabEPSS 0.5%CVE-2024-40119HIGHNepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability EPSS 0.5%CVE-2022-36379HIGHWordPress ЮKassa для WooCommerce plugin <= 2.3.0 - Cross-Site Request Forgery (CSRF) leading to plugin settings updateEPSS 0.5%CVE-2019-10199MEDIUMIt was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use thEPSS 0.5%CVE-2023-0999MEDIUMSourceCodester Sales Tracker Management System cross-site request forgeryEPSS 0.5%CVE-2017-7917A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HEPSS 0.5%CVE-2024-33449CRITICALAn SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary code via a POST requestEPSS 0.5%CVE-2022-23975MEDIUMWordPress Access Demo Importer plugin <= 1.0.7 - Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary Plugin ActivationEPSS 0.5%CVE-2016-10529Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafteEPSS 0.5%CVE-2021-38342HIGHNested Pages <= 3.1.15 Cross-Site Request Forgery to Arbitrary Post Deletion and ModificationEPSS 0.5%