CWE-352 跨站请求伪造(CSRF) 类弱点 4910 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-46911 | Apache Roller 跨站请求伪造漏洞 — Apache Roller | 8.8AI | HighAI | 2024-10-14 |
| CVE-2024-6959 | LoLLMS 安全漏洞 — parisneo/lollms-webui | 7.5 | - | 2024-10-13 |
| CVE-2024-9778 | WordPress plugin ImagePress 跨站请求伪造漏洞 — ImagePress – Image Gallery | 4.3 | Medium | 2024-10-12 |
| CVE-2024-9592 | WordPress plugin Easy PayPal Gift Certificate 跨站请求伪造漏洞 — Easy PayPal Gift Certificate | 6.1 | Medium | 2024-10-12 |
| CVE-2024-8477 | WordPress plugin Newsletter, SMTP, Email marketing and Subscribe forms by Brevo 安全漏洞 — Brevo – Email, SMS, Web Push, Chat, and more. | 4.3 | Medium | 2024-10-10 |
| CVE-2024-47828 | Ampache 安全漏洞 — ampache | 5.3 | Medium | 2024-10-09 |
| CVE-2024-44028 | WordPress plugin NiceJob 跨站请求伪造漏洞 — NiceJob | 7.1 | High | 2024-10-06 |
| CVE-2024-47635 | WordPress plugin TinyPNG 跨站请求伪造漏洞 — TinyPNG | 5.4 | Medium | 2024-10-05 |
| CVE-2024-47846 | MediaWiki 安全漏洞 — Mediawiki - Cargo | 8.8 | - | 2024-10-05 |
| CVE-2024-43684 | Microchip TimeProvider 4100 安全漏洞 — TimeProvider 4100 | 7.1 | - | 2024-10-04 |
| CVE-2024-8520 | WordPress plugin Ultimate Member 安全漏洞 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | 5.3 | Medium | 2024-10-04 |
| CVE-2024-41987 | TEM Opera Plus FM Family Transmitter 跨站请求伪造漏洞 — Opera Plus FM Family Transmitter | 8.8 | - | 2024-10-03 |
| CVE-2024-42504 | Hewlett Packard Enterprise IceWall Agent 安全漏洞 — HPE IceWall Agent products | 4.3 | Medium | 2024-10-03 |
| CVE-2023-7273 | ownCloud 安全漏洞 — OwnCloud | 6.8 | Medium | 2024-10-01 |
| CVE-2024-8458 | PLANET switch devices 跨站请求伪造漏洞 — GS-4210-24PL4C hardware 2.0 | 8.8 | High | 2024-09-30 |
| CVE-2024-28948 | Advantech ADAM-5630 跨站请求伪造漏洞 — ADAM-5630 | 8.0 | High | 2024-09-27 |
| CVE-2024-9282 | MiniCMS 跨站请求伪造漏洞 — MiniCMS | 4.3 | Medium | 2024-09-27 |
| CVE-2024-9281 | MiniCMS 跨站请求伪造漏洞 — MiniCMS | 4.3 | Medium | 2024-09-27 |
| CVE-2024-45372 | Planex MZK-MF300N 安全漏洞 — MZK-DP300N | 8.0AI | HighAI | 2024-09-26 |
| CVE-2024-47082 | Strawberry GraphQL 跨站请求伪造漏洞 — strawberry | 4.6 | Medium | 2024-09-25 |
| CVE-2024-47305 | WordPress plugin Use Any Font 跨站请求伪造漏洞 — Use Any Font | 4.3 | Medium | 2024-09-25 |
| CVE-2024-47315 | WordPress plugin GiveWP 安全漏洞 — GiveWP | 5.4 | Medium | 2024-09-25 |
| CVE-2024-20437 | Cisco IOS XE Software 安全漏洞 — Cisco IOS XE Software | 8.1 | High | 2024-09-25 |
| CVE-2024-8476 | WordPress plugin Easy PayPal Events 跨站请求伪造漏洞 — Easy PayPal Events & Tickets | 4.3 | Medium | 2024-09-25 |
| CVE-2024-7386 | WordPress plugin Premium Packages – Sell Digital Products Securely 跨站请求伪造漏洞 — Premium Packages – Sell Digital Products Securely | 4.3 | Medium | 2024-09-25 |
| CVE-2024-8795 | WordPress plugin BA Book Everything 跨站请求伪造漏洞 — BA Book Everything | 8.8 | High | 2024-09-24 |
| CVE-2024-8490 | WordPress plugin PropertyHive 跨站请求伪造漏洞 — Property Hive | 8.8 | High | 2024-09-17 |
| CVE-2024-6862 | Lunary 跨站请求伪造漏洞 — lunary-ai/lunary | 8.8AI | HighAI | 2024-09-13 |
| CVE-2024-7423 | WordPress plugin Stream 跨站请求伪造漏洞 — Stream | 8.8 | High | 2024-09-13 |
| CVE-2023-2919 | WordPress plugin Tutor LMS 跨站请求伪造漏洞 — Tutor LMS – eLearning and online course solution | 4.3 | Medium | 2024-09-10 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4910 条 CVE 漏洞。