Falhas do tipo CWE-352

6.057 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2021-36877MEDIUMWordPress uListing plugin <= 2.0.5 - Modify User Roles via Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2022-46688MEDIUMA cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have JenkEPSS 0.4%CVE-2021-22950—Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for dEPSS 0.4%CVE-2024-6309HIGHAttachment File Icons (AF Icons) <= 1.3 - Cross-Site Request Forgery to Arbitrary File UploadEPSS 0.4%CVE-2019-3864MEDIUMA vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameteEPSS 0.4%CVE-2020-36745MEDIUMWP Project Manager <= 2.4.0 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2021-4030HIGHA cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitraryEPSS 0.4%CVE-2022-0245MEDIUMCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchatEPSS 0.4%CVE-2021-36878MEDIUMWordPress uListing plugin <= 2.0.5 - Settings Update via Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2025-47204MEDIUMAn issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitEPSS 0.4%CVE-2020-19803HIGHCross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the backgroundEPSS 0.4%CVE-2021-36850MEDIUMWordPress Media File Renamer – Auto & Manual Rename plugin <= 5.1.9 - Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2023-3029MEDIUMGuangdong Pythagorean OA Office System delete cross-site request forgeryEPSS 0.4%CVE-2022-41236HIGHA cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to repEPSS 0.4%CVE-2024-6320HIGHScrollTo Top <= 1.2.2 - Cross-Site Request Forgery to Arbitrary File UploadEPSS 0.4%CVE-2024-6321HIGHScrollTo Bottom <= 1.1.1 - Cross-Site Request Forgery to Arbitrary File UploadEPSS 0.4%CVE-2022-2260—GiveWP < 2.21.3 - DoS via CSRFEPSS 0.4%CVE-2023-4865MEDIUMSourceCodester Take-Note App cross-site request forgeryEPSS 0.4%CVE-2023-4868MEDIUMSourceCodester Contact Manager App add.php cross-site request forgeryEPSS 0.4%CVE-2022-20961HIGHA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.4%