CWE-352 跨站请求伪造(CSRF) 类弱点 4920 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-28195 | YourSpotify 安全漏洞 — your_spotify | 8.1 | High | 2024-03-13 |
| CVE-2024-1489 | WordPress Plugin SMS Alert Order Notifications 安全漏洞 — SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | 4.3 | Medium | 2024-03-13 |
| CVE-2024-0827 | WordPress Plugin Play.ht 安全漏洞 — Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio | 4.3 | Medium | 2024-03-13 |
| CVE-2024-0830 | WordPress Plugin Comments Extra Fields For Post,Pages and CPT 安全漏洞 — Comments Extra Fields For Post,Pages and CPT | 4.3 | Medium | 2024-03-13 |
| CVE-2024-0592 | WordPress Plugin Related Posts for WordPress 安全漏洞 — Related Posts for WordPress | 5.4 | Medium | 2024-03-13 |
| CVE-2024-1642 | WordPress Plugin MainWP Dashboard 安全漏洞 — MainWP Dashboard: Self-hosted WordPress Management for Agencies | 4.3 | Medium | 2024-03-13 |
| CVE-2024-2416 | Movistar 4G router 跨站请求伪造漏洞 — Router Movistar 4G | 6.5 | Medium | 2024-03-13 |
| CVE-2024-1214 | WordPress Plugin Easy Social Feed 安全漏洞 — Easy Social Feed – Social Photos Gallery and Post Feed for WordPress | 4.3 | Medium | 2024-03-12 |
| CVE-2024-1213 | WordPress Plugin Easy Social Feed 安全漏洞 — Easy Social Feed – Social Photos Gallery and Post Feed for WordPress | 5.4 | Medium | 2024-03-12 |
| CVE-2024-1503 | WordPress Plugin Tutor LMS 安全漏洞 — Tutor LMS – eLearning and online course solution | 4.3 | Medium | 2024-03-12 |
| CVE-2023-4629 | WordPress Plugin LadiApp 安全漏洞 — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | 4.3 | Medium | 2024-03-12 |
| CVE-2023-4729 | WordPress Plugin LadiApp 安全漏洞 — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | 4.3 | Medium | 2024-03-12 |
| CVE-2023-4731 | WordPress Plugin LadiApp安全漏洞 — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | 4.3 | Medium | 2024-03-12 |
| CVE-2023-4628 | WordPress Plugin LadiApp 安全漏洞 — LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | 4.3 | Medium | 2024-03-12 |
| CVE-2024-2354 | Dreamer CMS 跨站请求伪造漏洞 — CMS | 4.3 | Medium | 2024-03-10 |
| CVE-2024-2316 | BDTASK Hospital AutoManager 跨站请求伪造漏洞 — Hospital AutoManager | 4.3 | Medium | 2024-03-08 |
| CVE-2024-2277 | BDTASK G-Prescription Gynaecology & OBS Consultation Software 跨站请求伪造漏洞 — G-Prescription Gynaecology & OBS Consultation Software | 4.3 | Medium | 2024-03-08 |
| CVE-2024-1760 | WordPress Plugin Appointment Booking Calendar 安全漏洞 — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | 4.3 | Medium | 2024-03-06 |
| CVE-2024-2134 | Bdtask Hospita AutoManager 跨站请求伪造漏洞 — Hospita AutoManager | 4.3 | Medium | 2024-03-03 |
| CVE-2023-6326 | WordPress Plugin Master Slider 安全漏洞 — Master Slider – Responsive Touch Slider | 5.4 | Medium | 2024-03-02 |
| CVE-2024-1592 | WordPress Plugin Complianz 安全漏洞 — Complianz – GDPR/CCPA Cookie Consent | 4.3 | Medium | 2024-03-02 |
| CVE-2023-28949 | IBM Engineering Requirements Management DOORS Next 跨站请求伪造漏洞 — Engineering Requirements Management | 6.5 | Medium | 2024-03-01 |
| CVE-2024-1976 | WordPress Plugin Marketing Optimizer plugin for WordPress 安全漏洞 — Marketing Optimizer | 4.3 | Medium | 2024-02-29 |
| CVE-2024-21752 | WordPress Plugin Ajax Search Lite 安全漏洞 — Ajax Search Lite | 7.1 | High | 2024-02-29 |
| CVE-2023-51531 | WordPress Plugin Thrive Automator 跨站请求伪造漏洞 — Thrive Automator | 5.4 | Medium | 2024-02-29 |
| CVE-2023-51530 | WordPress Plugin Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation 跨站请求伪造漏洞 — Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation | 4.3 | Medium | 2024-02-29 |
| CVE-2023-51529 | WordPress Plugin HT Mega – Absolute Addons For Elementor 跨站请求伪造漏洞 — HT Mega – Absolute Addons For Elementor | 4.3 | Medium | 2024-02-29 |
| CVE-2023-51528 | WordPress Plugin AI Power: Complete AI Pack – Powered by GPT-4 跨站请求伪造漏洞 — AI Power: Complete AI Pack – Powered by GPT-4 | 4.3 | Medium | 2024-02-29 |
| CVE-2023-51696 | WordPress Plugin Spam protection, Anti-Spam, FireWall by CleanTalk 跨站请求伪造漏洞 — Spam protection, Anti-Spam, FireWall by CleanTalk | 4.3 | Medium | 2024-02-29 |
| CVE-2024-23910 | ELECOM WRC-1167GS2-B 安全漏洞 — WRC-1167GS2-B | 8.8AI | HighAI | 2024-02-28 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4920 条 CVE 漏洞。