Skip to content
Noroxi

CWE-352 · 9,466 records

Cross-site request forgery

Why does it happen?

State-changing requests rely on the session cookie the browser sends automatically; nothing verifies that the request came from the user’s own page.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

ts
app.use(session({ cookie: { httpOnly: true } }));app.post("/account/address", updateAddress);

Fixed

ts
app.use(session({ cookie: { httpOnly: true, sameSite: "lax" } }));app.post("/account/address", csrfProtection, updateAddress);

How to prevent it

  1. 01Add an anti-CSRF token to every state-changing request.
  2. 02Use the SameSite attribute on session cookies.
  3. 03Require re-authentication for critical actions.

CVEs in this class

9,469 records

  • NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    netgear · d6220 firmwareDec 14, 2016

  • CVE-2014-100005
    75This week

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.

    HighCVSS 8.0KEVWeaponizedEPSS 43%

    dlink · dir-600 firmwareJan 13, 2015

  • CVE-2023-2533
    74This week

    PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF

    HighCVSS 8.8KEVWeaponizedEPSS 29%

    papercut · papercut mfJun 20, 2023

  • CVE-2020-10181
    73This week

    goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (admini

    CriticalCVSS 9.8KEVWeaponizedEPSS 15%

    sumavision · enhanced multimedia router firmwareMar 11, 2020

  • CVE-2008-4128
    72This week

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Serv

    HighCVSS 8.1KEVWeaponizedEPSS 34%

    cisco · iosSep 18, 2008

  • CVE-2022-41622
    63This week

    iControl SOAP vulnerability

    HighCVSS 8.8WeaponizedEPSS 92%

    f5 · big-iq centralized managementDec 7, 2022

  • DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify

    HighCVSS 8.8Proof of conceptEPSS 74%

    dedecms · dedecmsMar 27, 2018

  • The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external ent

    MediumCVSS 6.8No exploitEPSS 91%

    springsource · spring frameworkApr 17, 2014

  • The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entit

    MediumCVSS 6.8No exploitEPSS 91%

    pivotal software · spring frameworkJan 26, 2014

  • diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.

    HighCVSS 8.8Proof of conceptEPSS 55%

    netgate · pfsenseSep 26, 2019

  • Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote

    MediumCVSS 6.8Proof of conceptEPSS 66%

    netgate · pfsenseApr 10, 2015

  • WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf

    HighCVSS 8.8Proof of conceptEPSS 39%

    wordpress · wordpressMar 14, 2019

  • Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call

    CriticalCVSS 9.8Proof of conceptEPSS 26%

    codeastrology · woo product tableApr 18, 2022

  • Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentic

    MediumCVSS 6.8Proof of conceptEPSS 65%

    igniterealtime · openfireSep 16, 2015

  • A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administ

    HighCVSS 8.8Proof of conceptEPSS 34%

    irz · ru21 firmwareMar 19, 2022

  • Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

    HighCVSS 8.8Proof of conceptEPSS 33%

    apache · ofbizApr 30, 2020

  • pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar

    HighCVSS 8.8WeaponizedEPSS 32%

    netgate · pfsenseJan 3, 2018

  • Apache JSPWiki CSRF in UserPreferences.jsp

    MediumCVSS 6.5No exploitEPSS 58%

    apache · jspwikiAug 4, 2022

  • Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for re

    HighCVSS 8.8WeaponizedEPSS 25%

    cisco · linksys wrt110 firmwareFeb 6, 2020

  • HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload

    CriticalCVSS 9.8Proof of conceptEPSS 12%

    html2wp project · html2wpJun 27, 2022

  • XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks

    HighCVSS 8.8Proof of conceptEPSS 23%

    xwiki · admin toolsNov 20, 2023

  • org.xwiki.contrib:application-ckeditor-ui vulnerable to Remote Code Execution via Cross-Site Request Forgery

    HighCVSS 8.8No exploitEPSS 19%

    xwiki · ckeditor integrationJan 4, 2023

  • PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    publishpress · capabilitiesJan 10, 2022

  • The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    mybb · mybbNov 10, 2017

  • A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    smartbear · swagger uiOct 10, 2019

All vulnerability classes