CWE-352 跨站请求伪造(CSRF) 类弱点 4920 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-47785 | WordPress Plugin LayerSlider 跨站请求伪造漏洞 — LayerSlider | 7.1 | High | 2023-11-22 |
| CVE-2023-47781 | WordPress Plugin Thriving 跨站请求伪造漏洞 — Thrive Theme Builder | 8.8 | High | 2023-11-22 |
| CVE-2023-47775 | WordPress Plugin Comments – wpDiscuz 跨站请求伪造漏洞 — Comments — wpDiscuz | 4.3 | Medium | 2023-11-22 |
| CVE-2023-47765 | WordPress Plugin CodeBard s Patron Button and Widgets for Patreon 跨站请求伪造漏洞 — CodeBard's Patron Button and Widgets for Patreon | 4.3 | Medium | 2023-11-22 |
| CVE-2023-47758 | WordPress Plugin Multi Step Form 跨站请求伪造漏洞 — Multi Step Form | 5.4 | Medium | 2023-11-22 |
| CVE-2023-25986 | WordPress Plugin PayGreen – Ancienne version 跨站请求伪造漏洞 — PayGreen – Ancienne version | 4.3 | Medium | 2023-11-22 |
| CVE-2023-25987 | WordPress Plugin My YouTube Channel 跨站请求伪造漏洞 — My YouTube Channel | 4.3 | Medium | 2023-11-22 |
| CVE-2023-2497 | WordPress Plugin UserPro 安全漏洞 — UserPro - Community and User Profile WordPress Plugin | 8.8 | High | 2023-11-22 |
| CVE-2023-6008 | WordPress Plugin UserPro 安全漏洞 — UserPro - Community and User Profile WordPress Plugin | 6.3 | Medium | 2023-11-22 |
| CVE-2023-5383 | WordPress Plugin Funnelforms Free 安全漏洞 — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | 4.3 | Medium | 2023-11-22 |
| CVE-2023-2438 | WordPress Plugin UserPro 安全漏洞 — UserPro - Community and User Profile WordPress Plugin | 6.1 | Medium | 2023-11-22 |
| CVE-2023-2440 | WordPress Plugin UserPro 安全漏洞 — UserPro - Community and User Profile WordPress Plugin | 8.8 | High | 2023-11-22 |
| CVE-2023-5382 | WordPress Plugin Funnelforms Free 安全漏洞 — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | 6.5 | Medium | 2023-11-22 |
| CVE-2023-5537 | WordPress Plugin Delete Usermeta 安全漏洞 — Delete Usermetas | 4.3 | Medium | 2023-11-22 |
| CVE-2023-26542 | WordPress Plugin phpinfo() WP 跨站请求伪造漏洞 — phpinfo() WP | 5.4 | Medium | 2023-11-22 |
| CVE-2023-26535 | WordPress Plugin Sheets To WP Table Live Sync 安全漏洞 — Sheets To WP Table Live Sync | 5.4 | Medium | 2023-11-22 |
| CVE-2023-26532 | WordPress Plugin Social Auto Poster 安全漏洞 — Social Auto Poster | 5.4 | Medium | 2023-11-22 |
| CVE-2023-27457 | WordPress Plugin Add Expires Headers & Optimized Minify 安全漏洞 — Add Expires Headers & Optimized Minify | 4.3 | Medium | 2023-11-22 |
| CVE-2023-27458 | WordPress Plugin WpStream 安全漏洞 — WpStream | 4.3 | Medium | 2023-11-22 |
| CVE-2023-27461 | WordPress Plugin When Last Login 安全漏洞 — When Last Login | 4.3 | Medium | 2023-11-22 |
| CVE-2023-27453 | WordPress Plugin LWS Tools 安全漏洞 — LWS Tools | 5.4 | Medium | 2023-11-22 |
| CVE-2023-27442 | WordPress Plugin Leyka 安全漏洞 — Leyka | 5.4 | Medium | 2023-11-22 |
| CVE-2023-27444 | WordPress Plugin DecaLog 安全漏洞 — DecaLog | 4.3 | Medium | 2023-11-22 |
| CVE-2023-27446 | WordPress Plugin DeepL API translation plugin 安全漏洞 — DeepL API translation plugin | 4.3 | Medium | 2023-11-22 |
| CVE-2023-27633 | WordPress Plugin Customify 安全漏洞 — Customify – Intuitive Website Styling | 4.3 | Medium | 2023-11-22 |
| CVE-2023-28747 | WordPress Plugin CBX Currency Converter 安全漏洞 — CBX Currency Converter | 5.4 | Medium | 2023-11-22 |
| CVE-2023-28749 | WordPress Plugin CM On Demand Search And Replace 安全漏洞 — CM On Demand Search And Replace | 4.3 | Medium | 2023-11-22 |
| CVE-2023-2447 | WordPress Plugin UserPro 安全漏洞 — UserPro - Community and User Profile WordPress Plugin | 6.1 | Medium | 2023-11-22 |
| CVE-2022-35638 | IBM Sterling B2B Integrator 安全漏洞 — Sterling B2B Integrator | 4.3 | Medium | 2023-11-22 |
| CVE-2023-5776 | WordPress Plugin Post Meta Data Manager 安全漏洞 — Post Meta Data Manager | 4.3 | Medium | 2023-11-21 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4920 条 CVE 漏洞。