Falhas do tipo CWE-352

5.848 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2021-24174Database Backups <= 1.2.2.6 - CSRF to Backup DownloadEPSS 3.2%CVE-2019-13529HIGHAn attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissioEPSS 3.1%CVE-2020-13569HIGHA cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f6EPSS 3.0%CVE-2021-26296Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFacesEPSS 3.0%CVE-2005-1674MEDIUMCross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a liEPSS 2.9%CVE-2017-5264Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrativEPSS 2.7%CVE-2022-4944MEDIUMkalcaddle KodExplorer cross-site request forgeryEPSS 2.7%CVE-2021-34620HIGHCSRF in WP Fluent Forms < 3.6.67 allows stored XSS and Privilege EscalationEPSS 2.6%CVE-2024-13913HIGHInstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.83 - Cross-Site Request Forgery to Local File InclusionEPSS 2.4%CVE-2020-5397MEDIUMCSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFluxEPSS 2.4%CVE-2018-16854MEDIUMA flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by EPSS 2.3%CVE-2022-21703MEDIUMCross Site Request Forgery in GrafanaEPSS 2.2%CVE-2020-10890HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interacEPSS 2.2%CVE-2020-10892HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interacEPSS 2.2%CVE-2022-0088LOWCross-Site Request Forgery (CSRF) in yourls/yourlsEPSS 2.0%CVE-2018-12540In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form pEPSS 2.0%CVE-2022-41413MEDIUMperfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted iEPSS 2.0%CVE-2018-4066An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A EPSS 1.9%CVE-2021-24272Fitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS)EPSS 1.8%CVE-2020-4040HIGHCSRF issue on preview pages in Bolt CMSEPSS 1.8%