Falhas do tipo CWE-352

6.050 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2018-0255A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker toEPSS 0.9%CVE-2018-10884HIGHAnsible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker cEPSS 0.9%CVE-2016-7067MEDIUMMonit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disableEPSS 0.9%CVE-2025-49555HIGHAdobe Commerce | Cross-Site Request Forgery (CSRF) (CWE-352)EPSS 0.9%CVE-2018-8844Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a weEPSS 0.9%CVE-2018-0363A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could alEPSS 0.9%CVE-2016-6578CodeLathe FileCloud, version 13.0.0.32841 and earlier, is vulnerable to cross-site request forgery (CSRF)EPSS 0.9%CVE-2017-9641PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that useEPSS 0.9%CVE-2019-3809MEDIUMA flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of EPSS 0.9%CVE-2023-35141HIGHIn Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the UEPSS 0.9%CVE-2024-20252CRITICALMultiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, EPSS 0.8%CVE-2016-6557The ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, is vulnerable to cross-site request forgeryEPSS 0.8%CVE-2018-0215A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.8%CVE-2022-1969HIGHMobile browser color select <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.8%CVE-2021-1257HIGHCisco DNA Center Cross-Site Request Forgery VulnerabilityEPSS 0.8%CVE-2018-0216A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.8%CVE-2014-0594HIGHCSRF protection incorrectly disabledEPSS 0.8%CVE-2018-0107A vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unwanted actiEPSS 0.8%CVE-2018-0148A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) SupervEPSS 0.8%CVE-2017-6756A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, reEPSS 0.8%