CWE-352 · 9.466 kayıt
Siteler arası istek sahteciliği
Neden olur?
Durum değiştiren istekler tarayıcının otomatik gönderdiği oturum çerezine dayanıyor; isteğin kullanıcının kendi sayfasından geldiği doğrulanmıyor.
Hatalı ve düzeltilmiş kod
Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.
Hatalı
app.use(session({ cookie: { httpOnly: true } }));app.post("/account/address", updateAddress);Düzeltilmiş
app.use(session({ cookie: { httpOnly: true, sameSite: "lax" } }));app.post("/account/address", csrfProtection, updateAddress);Nasıl önlenir?
- 01Durum değiştiren her isteğe istek sahteciliği belirteci ekleyin.
- 02Oturum çerezlerinde SameSite özniteliğini kullanın.
- 03Kritik işlemlerde yeniden kimlik doğrulama isteyin.
Bu sınıftaki CVE’ler
9.469 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2016-6277Silahlaştırılmış | NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before netgear · d6220 firmware · CWE-352 | Yüksek8,8 | KEV | %99,8 | 14 Ara 2016 |
75Bu hafta | CVE-2014-100005Silahlaştırılmış | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.dlink · dir-600 firmware · CWE-352 | Yüksek8,0 | KEV | %43,5 | 13 Oca 2015 |
74Bu hafta | CVE-2023-2533Silahlaştırılmış | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRFpapercut · papercut mf · CWE-352 | Yüksek8,8 | KEV | %29,2 | 20 Haz 2023 |
73Bu hafta | CVE-2020-10181Silahlaştırılmış | goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (adminisumavision · enhanced multimedia router firmware · CWE-352 | Kritik9,8 | KEV | %14,7 | 11 Mar 2020 |
72Bu hafta | CVE-2008-4128Silahlaştırılmış | Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Servcisco · ios · CWE-352 | Yüksek8,1 | KEV | %33,9 | 18 Eyl 2008 |
63Bu hafta | CVE-2022-41622Silahlaştırılmış | iControl SOAP vulnerabilityf5 · big-iq centralized management · CWE-352 | Yüksek8,8 | — | %92,3 | 7 Ara 2022 |
57Planlayın | CVE-2018-7700Kavram kanıtı | DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specifydedecms · dedecms · CWE-352 | Yüksek8,8 | — | %74,1 | 27 Mar 2018 |
54Planlayın | CVE-2014-0054İstismar yok | The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entspringsource · spring framework · CWE-352 | Orta6,8 | — | %91,4 | 17 Nis 2014 |
54Planlayın | CVE-2013-6429İstismar yok | The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entitpivotal software · spring framework · CWE-352 | Orta6,8 | — | %90,6 | 26 Oca 2014 |
51Planlayın | CVE-2019-16667Kavram kanıtı | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.netgate · pfsense · CWE-352 | Yüksek8,8 | — | %54,5 | 26 Eyl 2019 |
47Planlayın | CVE-2015-2295Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remotenetgate · pfsense · CWE-352 | Orta6,8 | — | %65,7 | 10 Nis 2015 |
47Planlayın | CVE-2019-9787Kavram kanıtı | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default confwordpress · wordpress · CWE-352 | Yüksek8,8 | — | %38,7 | 14 Mar 2019 |
47Planlayın | CVE-2022-1020Kavram kanıtı | Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Callcodeastrology · woo product table · CWE-352 | Kritik9,8 | — | %25,9 | 18 Nis 2022 |
46Planlayın | CVE-2015-6973Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authenticigniterealtime · openfire · CWE-352 | Orta6,8 | — | %64,8 | 16 Eyl 2015 |
45Planlayın | CVE-2022-27226Kavram kanıtı | A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administirz · ru21 firmware · CWE-352 | Yüksek8,8 | — | %33,7 | 19 Mar 2022 |
45Planlayın | CVE-2019-0235Kavram kanıtı | Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.apache · ofbiz · CWE-352 | Yüksek8,8 | — | %32,7 | 30 Nis 2020 |
45Planlayın | CVE-2017-1000479Silahlaştırılmış | pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrarnetgate · pfsense · CWE-352 | Yüksek8,8 | — | %31,7 | 3 Oca 2018 |
43Planlayın | CVE-2022-28731İstismar yok | Apache JSPWiki CSRF in UserPreferences.jspapache · jspwiki · CWE-352 | Orta6,5 | — | %57,8 | 4 Ağu 2022 |
43Planlayın | CVE-2013-3568Silahlaştırılmış | Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for recisco · linksys wrt110 firmware · CWE-352 | Yüksek8,8 | — | %25,1 | 6 Şub 2020 |
43Planlayın | CVE-2022-1574Kavram kanıtı | HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Uploadhtml2wp project · html2wp · CWE-352 | Kritik9,8 | — | %12,2 | 27 Haz 2022 |
42Planlayın | CVE-2023-48292Kavram kanıtı | XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacksxwiki · admin tools · CWE-352 | Yüksek8,8 | — | %22,9 | 20 Kas 2023 |
41Planlayın | CVE-2023-22457İstismar yok | org.xwiki.contrib:application-ckeditor-ui vulnerable to Remote Code Execution via Cross-Site Request Forgeryxwiki · ckeditor integration · CWE-352 | Yüksek8,8 | — | %18,7 | 4 Oca 2023 |
41Planlayın | CVE-2021-25032Kavram kanıtı | PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromisepublishpress · capabilities · CWE-352 | Kritik9,8 | — | %6,7 | 10 Oca 2022 |
41Planlayın | CVE-2017-16780Kavram kanıtı | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.mybb · mybb · CWE-352 | Kritik9,8 | — | %5,8 | 10 Kas 2017 |
41Planlayın | CVE-2019-17495Kavram kanıtı | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPOsmartbear · swagger ui · CWE-352 | Kritik9,8 | — | %5,7 | 10 Eki 2019 |
- CVE-2016-627795Hemen
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100netgear · d6220 firmware14 Ara 2016
- CVE-2014-10000575Bu hafta
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.
YüksekCVSS 8,0KEVSilahlaştırılmışEPSS %43dlink · dir-600 firmware13 Oca 2015
- CVE-2023-253374Bu hafta
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %29papercut · papercut mf20 Haz 2023
- CVE-2020-1018173Bu hafta
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (admini
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %15sumavision · enhanced multimedia router firmware11 Mar 2020
- CVE-2008-412872Bu hafta
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Serv
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %34cisco · ios18 Eyl 2008
- CVE-2022-4162263Bu hafta
iControl SOAP vulnerability
YüksekCVSS 8,8SilahlaştırılmışEPSS %92f5 · big-iq centralized management7 Ara 2022
- CVE-2018-770057Planlayın
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify
YüksekCVSS 8,8Kavram kanıtıEPSS %74dedecms · dedecms27 Mar 2018
- CVE-2014-005454Planlayın
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external ent
OrtaCVSS 6,8İstismar yokEPSS %91springsource · spring framework17 Nis 2014
- CVE-2013-642954Planlayın
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entit
OrtaCVSS 6,8İstismar yokEPSS %91pivotal software · spring framework26 Oca 2014
- CVE-2019-1666751Planlayın
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.
YüksekCVSS 8,8Kavram kanıtıEPSS %55netgate · pfsense26 Eyl 2019
- CVE-2015-229547Planlayın
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote
OrtaCVSS 6,8Kavram kanıtıEPSS %66netgate · pfsense10 Nis 2015
- CVE-2019-978747Planlayın
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf
YüksekCVSS 8,8Kavram kanıtıEPSS %39wordpress · wordpress14 Mar 2019
- CVE-2022-102047Planlayın
Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call
KritikCVSS 9,8Kavram kanıtıEPSS %26codeastrology · woo product table18 Nis 2022
- CVE-2015-697346Planlayın
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentic
OrtaCVSS 6,8Kavram kanıtıEPSS %65igniterealtime · openfire16 Eyl 2015
- CVE-2022-2722645Planlayın
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administ
YüksekCVSS 8,8Kavram kanıtıEPSS %34irz · ru21 firmware19 Mar 2022
- CVE-2019-023545Planlayın
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
YüksekCVSS 8,8Kavram kanıtıEPSS %33apache · ofbiz30 Nis 2020
- CVE-2017-100047945Planlayın
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar
YüksekCVSS 8,8SilahlaştırılmışEPSS %32netgate · pfsense3 Oca 2018
- CVE-2022-2873143Planlayın
Apache JSPWiki CSRF in UserPreferences.jsp
OrtaCVSS 6,5İstismar yokEPSS %58apache · jspwiki4 Ağu 2022
- CVE-2013-356843Planlayın
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for re
YüksekCVSS 8,8SilahlaştırılmışEPSS %25cisco · linksys wrt110 firmware6 Şub 2020
- CVE-2022-157443Planlayın
HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload
KritikCVSS 9,8Kavram kanıtıEPSS %12html2wp project · html2wp27 Haz 2022
- CVE-2023-4829242Planlayın
XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks
YüksekCVSS 8,8Kavram kanıtıEPSS %23xwiki · admin tools20 Kas 2023
- CVE-2023-2245741Planlayın
org.xwiki.contrib:application-ckeditor-ui vulnerable to Remote Code Execution via Cross-Site Request Forgery
YüksekCVSS 8,8İstismar yokEPSS %19xwiki · ckeditor integration4 Oca 2023
- CVE-2021-2503241Planlayın
PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
KritikCVSS 9,8Kavram kanıtıEPSS %7publishpress · capabilities10 Oca 2022
- CVE-2017-1678041Planlayın
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
KritikCVSS 9,8Kavram kanıtıEPSS %6mybb · mybb10 Kas 2017
- CVE-2019-1749541Planlayın
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO
KritikCVSS 9,8Kavram kanıtıEPSS %6smartbear · swagger ui10 Eki 2019