Falhas do tipo CWE-352

6.062 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2021-23163LOWJFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issuEPSS 0.4%CVE-2020-7534HIGHA CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unautEPSS 0.4%CVE-2022-29430MEDIUMWordPress PNG to JPG plugin <= 4.0 - Cross-Site Request Forgery (CSRF) leading to Persistent Cross-Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2024-55921HIGHCross-Site Request Forgery in Extension Manager Module in TYPO3EPSS 0.4%CVE-2026-85547MEDIUMCross-Site Request Forgery via Attacker-Controlled REST Detection in MISPEPSS 0.4%CVE-2022-36798MEDIUMWordPress Mega Addons For WPBakery Page Builder plugin <= 4.2.7 - Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2023-28419MEDIUMWordPress Force First and Last Name as Display Name Plugin <= 1.2 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.4%CVE-2022-2375—WP Sticky Button < 1.4.1 - Unauthenticated Arbitrary Settings Update to Stored XSSEPSS 0.4%CVE-2023-23847LOWA cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an atEPSS 0.4%CVE-2026-40948MEDIUMApache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth ManagerEPSS 0.4%CVE-2021-22949—A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of dEPSS 0.4%CVE-2024-23785MEDIUMCross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allowEPSS 0.4%CVE-2021-22953—A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of diskEPSS 0.4%CVE-2024-9281MEDIUMbg5sbk MiniCMS post-edit.php cross-site request forgeryEPSS 0.4%CVE-2022-2377—Directorist < 7.3.0 - Subscriber+ Arbitrary E-mail SendingEPSS 0.4%CVE-2024-11673MEDIUM1000 Projects Bookstore Management System cross-site request forgeryEPSS 0.4%CVE-2022-2762MEDIUMAdminPad < 2.2 - Note Update via CSRFEPSS 0.4%CVE-2025-47410HIGHApache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target systemEPSS 0.4%CVE-2025-23797CRITICALWordPress WP Options Editor plugin <= 1.1 - CSRF to Privilege Escalation vulnerabilityEPSS 0.4%CVE-2024-7065MEDIUMSpina CMS cross-site request forgeryEPSS 0.4%