Falhas do tipo CWE-352

6.043 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2024-0379MEDIUMCustom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options UpdateEPSS 1.0%CVE-2009-3022MEDIUMCross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other uEPSS 1.0%CVE-2016-10522rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens andEPSS 1.0%CVE-2017-12271A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on aEPSS 1.0%CVE-2019-16009HIGHCisco IOS and Cisco IOS XE Software Web UI Cross-Site Request Forgery VulnerabilityEPSS 1.0%CVE-2019-1904HIGHCisco IOS XE Software Web UI Cross-Site Request Forgery VulnerabilityEPSS 1.0%CVE-2020-15259HIGHCSRF in Auth0 ad-ldap-connectorEPSS 1.0%CVE-2021-32732HIGHCross-Site Request Forgery in xwiki-platformEPSS 1.0%CVE-2015-20105ClickBank Affiliate Ads <= 1.20 - CSRF to Stored Cross-Site ScriptingEPSS 1.0%CVE-2024-0624MEDIUMPaid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders UpdateEPSS 1.0%CVE-2024-22416CRITICALCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalationEPSS 0.9%CVE-2018-0365A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker tEPSS 0.9%CVE-2018-15445MEDIUMCisco Energy Management Suite Cross-Site Request Forgery VulnerabilityEPSS 0.9%CVE-2020-8282A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have bEPSS 0.9%CVE-2022-29429HIGHWordPress Code Snippets Extended plugin <= 1.4.7 - Cross-Site Request Forgery (CSRF) leading to Remote Code Execution (RCE) vulnerabilityEPSS 0.9%CVE-2020-7005In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an aEPSS 0.9%CVE-2021-21241HIGHCSRF can expose users authentication token in Flask-Security-TooEPSS 0.9%CVE-2021-24639OMGF < 4.5.4 - Subscriber+ Arbitrary File/Folder DeletionEPSS 0.9%CVE-2025-49555HIGHAdobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)EPSS 0.9%CVE-2024-27448CRITICALMailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js EPSS 0.9%