Falhas do tipo CWE-352

6.058 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2024-4585MEDIUMDedeCMS member_type.php cross-site request forgeryEPSS 0.4%CVE-2022-2555—Yotpo Reviews for WooCommerce <= 2.0.4 - Arbitrary Settings Update via CSRFEPSS 0.4%CVE-2023-42323HIGHCross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code via the adminAction.clEPSS 0.4%CVE-2024-4593MEDIUMDedeCMS sys_multiserv.php cross-site request forgeryEPSS 0.4%CVE-2021-4049MEDIUMCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchatEPSS 0.4%CVE-2022-41489HIGHWAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the sEPSS 0.4%CVE-2022-3017MEDIUMCross-Site Request Forgery (CSRF) in froxlor/froxlorEPSS 0.4%CVE-2022-45149MEDIUMA vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's EPSS 0.4%CVE-2021-4417MEDIUMForminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 - Cross-Site Request Forgery BypassEPSS 0.4%CVE-2019-13920—A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not proEPSS 0.4%CVE-2017-20091MEDIUMFile Manager Plugin cross-site request forgeryEPSS 0.4%CVE-2017-20088MEDIUMAtahualpa Theme cross-site request forgeryEPSS 0.4%CVE-2023-2599LOWActive Directory Integration / LDAP Integration <= 4.1.4 - Cross-Site Request Forgery to SQL InjectionEPSS 0.4%CVE-2021-34167HIGHCross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.EPSS 0.4%CVE-2022-27847MEDIUMWordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Template ImportEPSS 0.4%CVE-2022-27846MEDIUMWordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Slider Creation / ModificationEPSS 0.4%CVE-2019-25064MEDIUMCoreHR Core Portal cross-site request forgeryEPSS 0.4%CVE-2024-55500HIGHCross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the exEPSS 0.4%CVE-2022-37719HIGHA Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and exeEPSS 0.4%CVE-2022-23983MEDIUMWordPress WP Content Copy Protection & No Right Click plugin <= 3.4.4 - Cross-Site Request Forgery (CSRF) leads to Settings Update vulnerabilityEPSS 0.4%