Falhas do tipo CWE-352

6.072 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2023-32978MEDIUMA cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server usEPSS 0.3%CVE-2026-32989HIGHPrecurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file uploadEPSS 0.3%CVE-2022-38660HIGHHCL XPages applications are susceptible to Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.3%CVE-2022-34654MEDIUMWordPress Manage Notification E-mails Plugin <= 1.8.2 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2025-53540HIGHCSRF Vulnerability in Firmware Update Endpoints Allows Remote Code ExecutionEPSS 0.3%CVE-2024-2354MEDIUMDreamer CMS toEdit cross-site request forgeryEPSS 0.3%CVE-2024-33830HIGHidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.EPSS 0.3%CVE-2024-42578HIGHA Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privilEPSS 0.3%CVE-2024-42764CRITICALKashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.EPSS 0.3%CVE-2024-40476HIGHA Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to aEPSS 0.3%CVE-2023-4959MEDIUMQuay: cross-site request forgery (csrf) on config-editor pageEPSS 0.3%CVE-2026-52823MEDIUMKimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized State ChangesEPSS 0.3%CVE-2022-32175MEDIUMAdGuardHome - CSRFEPSS 0.3%CVE-2024-3932LOWTotara LMS User Selector cross-site request forgeryEPSS 0.3%CVE-2024-20437HIGHA vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a EPSS 0.3%CVE-2025-25379CRITICALCross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the EPSS 0.3%CVE-2022-1626—Sharebar <= 1.4.1 - Arbitrary Settings Update to Stored XSS via CSRFEPSS 0.3%CVE-2023-47666MEDIUMWordPress Code Snippets Plugin <= 3.5.0 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2024-30560CRITICALWordPress DX-Watermark plugin <= 1.0.4 - CSRF to Arbitrary File Upload and XSS vulnerabilityEPSS 0.3%CVE-2024-1719MEDIUMEasy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 - Cross-Site Request Forgery to Settings UpdateEPSS 0.3%