İçeriğe atla
Noroxi

CWE-352 · 9.466 kayıt

Siteler arası istek sahteciliği

Neden olur?

Durum değiştiren istekler tarayıcının otomatik gönderdiği oturum çerezine dayanıyor; isteğin kullanıcının kendi sayfasından geldiği doğrulanmıyor.

Hatalı ve düzeltilmiş kod

Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.

Hatalı

ts
app.use(session({ cookie: { httpOnly: true } }));app.post("/account/address", updateAddress);

Düzeltilmiş

ts
app.use(session({ cookie: { httpOnly: true, sameSite: "lax" } }));app.post("/account/address", csrfProtection, updateAddress);

Nasıl önlenir?

  1. 01Durum değiştiren her isteğe istek sahteciliği belirteci ekleyin.
  2. 02Oturum çerezlerinde SameSite özniteliğini kullanın.
  3. 03Kritik işlemlerde yeniden kimlik doğrulama isteyin.

Bu sınıftaki CVE’ler

9.469 kayıt

  • NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    netgear · d6220 firmware14 Ara 2016

  • CVE-2014-100005
    75Bu hafta

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.

    YüksekCVSS 8,0KEVSilahlaştırılmışEPSS %43

    dlink · dir-600 firmware13 Oca 2015

  • CVE-2023-2533
    74Bu hafta

    PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %29

    papercut · papercut mf20 Haz 2023

  • CVE-2020-10181
    73Bu hafta

    goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (admini

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %15

    sumavision · enhanced multimedia router firmware11 Mar 2020

  • CVE-2008-4128
    72Bu hafta

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Serv

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %34

    cisco · ios18 Eyl 2008

  • CVE-2022-41622
    63Bu hafta

    iControl SOAP vulnerability

    YüksekCVSS 8,8SilahlaştırılmışEPSS %92

    f5 · big-iq centralized management7 Ara 2022

  • CVE-2018-7700
    57Planlayın

    DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify

    YüksekCVSS 8,8Kavram kanıtıEPSS %74

    dedecms · dedecms27 Mar 2018

  • CVE-2014-0054
    54Planlayın

    The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external ent

    OrtaCVSS 6,8İstismar yokEPSS %91

    springsource · spring framework17 Nis 2014

  • CVE-2013-6429
    54Planlayın

    The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entit

    OrtaCVSS 6,8İstismar yokEPSS %91

    pivotal software · spring framework26 Oca 2014

  • CVE-2019-16667
    51Planlayın

    diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.

    YüksekCVSS 8,8Kavram kanıtıEPSS %55

    netgate · pfsense26 Eyl 2019

  • CVE-2015-2295
    47Planlayın

    Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote

    OrtaCVSS 6,8Kavram kanıtıEPSS %66

    netgate · pfsense10 Nis 2015

  • CVE-2019-9787
    47Planlayın

    WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf

    YüksekCVSS 8,8Kavram kanıtıEPSS %39

    wordpress · wordpress14 Mar 2019

  • CVE-2022-1020
    47Planlayın

    Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call

    KritikCVSS 9,8Kavram kanıtıEPSS %26

    codeastrology · woo product table18 Nis 2022

  • CVE-2015-6973
    46Planlayın

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentic

    OrtaCVSS 6,8Kavram kanıtıEPSS %65

    igniterealtime · openfire16 Eyl 2015

  • CVE-2022-27226
    45Planlayın

    A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administ

    YüksekCVSS 8,8Kavram kanıtıEPSS %34

    irz · ru21 firmware19 Mar 2022

  • CVE-2019-0235
    45Planlayın

    Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

    YüksekCVSS 8,8Kavram kanıtıEPSS %33

    apache · ofbiz30 Nis 2020

  • CVE-2017-1000479
    45Planlayın

    pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar

    YüksekCVSS 8,8SilahlaştırılmışEPSS %32

    netgate · pfsense3 Oca 2018

  • CVE-2022-28731
    43Planlayın

    Apache JSPWiki CSRF in UserPreferences.jsp

    OrtaCVSS 6,5İstismar yokEPSS %58

    apache · jspwiki4 Ağu 2022

  • CVE-2013-3568
    43Planlayın

    Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for re

    YüksekCVSS 8,8SilahlaştırılmışEPSS %25

    cisco · linksys wrt110 firmware6 Şub 2020

  • CVE-2022-1574
    43Planlayın

    HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload

    KritikCVSS 9,8Kavram kanıtıEPSS %12

    html2wp project · html2wp27 Haz 2022

  • CVE-2023-48292
    42Planlayın

    XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks

    YüksekCVSS 8,8Kavram kanıtıEPSS %23

    xwiki · admin tools20 Kas 2023

  • CVE-2023-22457
    41Planlayın

    org.xwiki.contrib:application-ckeditor-ui vulnerable to Remote Code Execution via Cross-Site Request Forgery

    YüksekCVSS 8,8İstismar yokEPSS %19

    xwiki · ckeditor integration4 Oca 2023

  • CVE-2021-25032
    41Planlayın

    PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    publishpress · capabilities10 Oca 2022

  • CVE-2017-16780
    41Planlayın

    The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    mybb · mybb10 Kas 2017

  • CVE-2019-17495
    41Planlayın

    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    smartbear · swagger ui10 Eki 2019

Tüm zafiyet sınıfları