CWE-352 跨站请求伪造(CSRF) 类弱点 4920 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-52119 | WordPress Plugin Icegram Engage 安全漏洞 — Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52120 | WordPress Plugin NEX-Forms 跨站请求伪造漏洞 — NEX-Forms – Ultimate Form Builder – Contact forms and much more | 5.4 | Medium | 2024-01-05 |
| CVE-2023-52121 | WordPress Plugin NitroPack 跨站请求伪造漏洞 — NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images | 5.4 | Medium | 2024-01-05 |
| CVE-2023-52122 | WordPress Plugin Simple Job Board 安全漏洞 — Simple Job Board | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52123 | WordPress Plugin Strong Testimonials 跨站请求伪造漏洞 — Strong Testimonials | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52127 | WordPress Plugin WPC Product Bundles for WooCommerce 跨站请求伪造漏洞 — WPC Product Bundles for WooCommerce | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52128 | WordPress Plugin White Label 跨站请求伪造漏洞 — White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52129 | WordPress Plugin teachPress 跨站请求伪造漏洞 — teachPress | 6.3 | Medium | 2024-01-05 |
| CVE-2023-52130 | WordPress Plugin Affiliates Manager 跨站请求伪造漏洞 — Affiliates Manager | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52136 | WordPress Plugin Custom Twitter Feeds 跨站请求伪造漏洞 — Custom Twitter Feeds – A Tweets Widget or X Feed Widget | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52145 | WordPress Plugin Republish Old Posts 跨站请求伪造漏洞 — Republish Old Posts | 4.3 | Medium | 2024-01-05 |
| CVE-2023-52149 | WordPress Plugin Floating Button 跨站请求伪造漏洞 — Floating Button | 5.4 | Medium | 2024-01-05 |
| CVE-2023-52150 | WordPress Plugin Dynamic Content 安全漏洞 — Dynamic Content for Elementor | 8.8 | High | 2024-01-05 |
| CVE-2023-52184 | WordPress Plugin WP Job Portal 跨站请求伪造漏洞 — WP Job Portal – A Complete Job Board | 4.3 | Medium | 2024-01-05 |
| CVE-2023-6493 | WordPress plugin Depicter Slider 安全漏洞 — Depicter — Popup & Slider Builder | 4.3 | Medium | 2024-01-05 |
| CVE-2023-6984 | WordPress Plugin PowerPack Addons for Elementor 安全漏洞 — PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) | 5.3 | Medium | 2024-01-03 |
| CVE-2023-6980 | WordPress Plugin WP SMS 跨站请求伪造漏洞 — WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce | 4.3 | Medium | 2024-01-03 |
| CVE-2018-25096 | MdAlAmin-aol Own Health Record 跨站请求伪造漏洞 — Own Health Record | 4.3 | Medium | 2023-12-30 |
| CVE-2023-51545 | WordPress Plugin Job Manager & Career 代码问题漏洞 — Job Manager & Career – Manage job board listings, and recruitments | 9.6 | Critical | 2023-12-29 |
| CVE-2023-50878 | WordPress Plugin MStore API 跨站请求伪造漏洞 — MStore API | 5.4 | Medium | 2023-12-29 |
| CVE-2023-50902 | WordPress Plugin New User Approve 跨站请求伪造漏洞 — New User Approve | 4.3 | Medium | 2023-12-29 |
| CVE-2023-51354 | WordPress Plugin Appointment & Event Booking Calendar Plugin 跨站请求伪造漏洞 — Appointment & Event Booking Calendar Plugin – Webba Booking | 4.3 | Medium | 2023-12-29 |
| CVE-2023-51358 | WordPress Plugin Block IPs for Gravity Forms 跨站请求伪造漏洞 — Block IPs for Gravity Forms | 5.4 | Medium | 2023-12-29 |
| CVE-2023-51378 | WordPress Plugin Rise Blocks 跨站请求伪造漏洞 — Rise Blocks – A Complete Gutenberg Page Builder | 5.4 | Medium | 2023-12-29 |
| CVE-2023-51402 | WordPress Plugin ULTIMATE ADDONS 跨站请求伪造漏洞 — Ultimate Addons for WPBakery Page Builder | 4.3 | Medium | 2023-12-29 |
| CVE-2023-50858 | WordPress Plugin Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan 跨站请求伪造漏洞 — Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan | 5.4 | Medium | 2023-12-28 |
| CVE-2023-50873 | WordPress Plugin Add Any Extension to Pages 跨站请求伪造漏洞 — Add Any Extension to Pages | 4.3 | Medium | 2023-12-28 |
| CVE-2012-10017 | WordPress Plugin PlusCaptcha 跨站请求伪造漏洞 — Portfolio Plugin | 4.3 | Medium | 2023-12-26 |
| CVE-2023-7092 | Uniway UW-302VP 跨站请求伪造漏洞 — UW-302VP | 4.3 | Medium | 2023-12-24 |
| CVE-2023-5961 | MOXA ioLogik E1200 Series 跨站请求伪造漏洞 — ioLogik E1200 Series | 8.8 | High | 2023-12-23 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4920 条 CVE 漏洞。