CWE-352 跨站请求伪造(CSRF) 类弱点 4907 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2020-36761 | WordPress Plugin Top 10 跨站请求伪造漏洞 — WebberZone Top 10 — Popular Posts | 4.3 | Medium | 2023-07-12 |
| CVE-2020-36760 | WordPress Plugin Ocean Extra 跨站请求伪造漏洞 — Ocean Extra | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4425 | WordPress Plugin Defender Security 跨站请求伪造漏洞 — Defender Security – Malware Scanner, Login Security & Firewall | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4424 | WordPress Plugin Slider Hero 跨站请求伪造漏洞 — Slider Hero with Video Background, Animation | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4423 | WordPress Plugin RAYS Grid 跨站请求伪造漏洞 — RAYS Grid | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4422 | WordPress Plugin POST SMTP Mailer 跨站请求伪造漏洞 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4421 | WordPress Plugin Advanced Popups 跨站请求伪造漏洞 — Advanced Popups | 4.3 | Medium | 2023-07-12 |
| CVE-2020-36757 | WordPress Plugin WP Hotel Booking 跨站请求伪造漏洞 — WP Hotel Booking | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4420 | WordPress Plugin Sell Media 跨站请求伪造漏洞 — Sell Media | 4.3 | Medium | 2023-07-12 |
| CVE-2020-36756 | WordPress Plugin 10WebAnalytics 跨站请求伪造漏洞 — 10WebAnalytics | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4419 | WordPress Plugin WP-Backgrounds Lite 跨站请求伪造漏洞 — WP-Backgrounds Lite | 4.3 | Medium | 2023-07-12 |
| CVE-2023-3202 | WordPress Plugin MStore API 跨站请求伪造漏洞 — MStore API – Create Native Android & iOS Apps On The Cloud | 4.3 | Medium | 2023-07-12 |
| CVE-2023-2517 | WordPress Plugin Metform Elementor Contact Form Builder 跨站请求伪造漏洞 — MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | 5.4 | Medium | 2023-07-12 |
| CVE-2020-36752 | WordPress Plugin Coming Soon & Maintenance Mode Page 跨站请求伪造漏洞 — Coming Soon & Maintenance Mode Page & Under Construction | 4.3 | Medium | 2023-07-12 |
| CVE-2023-3199 | WordPress Plugin MStore API 跨站请求伪造漏洞 — MStore API – Create Native Android & iOS Apps On The Cloud | 4.3 | Medium | 2023-07-12 |
| CVE-2023-3011 | WordPress Plugin ARMember 跨站请求伪造漏洞 — ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | 6.5 | Medium | 2023-07-12 |
| CVE-2021-4417 | WordPress Plugin Forminator – Contact Form, Payment Form & Custom Form Builder 跨站请求伪造漏洞 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 5.4 | Medium | 2023-07-12 |
| CVE-2021-4416 | WordPress Plugin wp-mpdf 跨站请求伪造漏洞 — wp-mpdf | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4415 | WordPress Plugin Sunshine Photo Cart 跨站请求伪造漏洞 — Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4414 | WordPress Plugin Abandoned Cart Lite for WooCommerce 跨站请求伪造漏洞 — Abandoned Cart Lite for WooCommerce | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4413 | WordPress Plugin Process Steps Template Designer 跨站请求伪造漏洞 — Process Steps Template Designer | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4412 | WordPress Plugin WP Prayer 跨站请求伪造漏洞 — WP Prayer | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4411 | WordPress Plugin WP EasyPay – Square for WordPress 跨站请求伪造漏洞 — WP Easy Pay – Payment and Donation form Builder for Square | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4410 | WordPress Plugin Qtranslate Slug 跨站请求伪造漏洞 — Qtranslate Slug | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4409 | WordPress Plugin WooCommerce Etsy Integration 跨站请求伪造漏洞 — Etsy Integration For WooCommerce | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4408 | WordPress Plugin DW Question & Answer 跨站请求伪造漏洞 — DW Question & Answer | 4.3 | Medium | 2023-07-12 |
| CVE-2021-4407 | WordPress Plugin Custom Banners 跨站请求伪造漏洞 — Custom Banners | 4.3 | Medium | 2023-07-12 |
| CVE-2020-36750 | WordPress Plugin EWWW Image Optimizer 跨站请求伪造漏洞 — EWWW Image Optimizer | 4.3 | Medium | 2023-07-12 |
| CVE-2023-3627 | SuiteCRM 跨站请求伪造漏洞 — salesagility/suitecrm-core | 6.5 | - | 2023-07-11 |
| CVE-2023-2746 | Rockwell Automation Enhanced HIM 跨站请求伪造漏洞 — Enhanced HIM | 9.6 | Critical | 2023-07-11 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4907 条 CVE 漏洞。