CWE-352 跨站请求伪造(CSRF) 类弱点 4853 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-0107 | Cisco Prime Service Catalog 跨站脚本漏洞 — Cisco Prime Service Catalog | 8.8 | - | 2018-01-18 |
| CVE-2017-5263 | Cambium Networks cnPilot 安全漏洞 — cnPilot | 8.8 | - | 2017-12-20 |
| CVE-2017-5264 | Rapid7 Nexpose 安全漏洞 — Nexpose | 8.8 | - | 2017-12-14 |
| CVE-2017-12271 | Cisco SPA300和SPA500 Series IP Phones 跨站请求伪造漏洞 — Cisco SPA300 and SPA500 Series IP Phones | 8.8 | - | 2017-10-19 |
| CVE-2017-14011 | ProMinent MultiFLEX M10a Controller Web界面跨站请求伪造漏洞 — ProMinent MultiFLEX M10a Controller | 8.8 | - | 2017-10-17 |
| CVE-2017-12253 | Cisco Unified Intelligence Center 跨站请求伪造漏洞 — Cisco Unified Intelligence Center | 8.8 | - | 2017-09-21 |
| CVE-2017-7926 | OSIsoft PI Web API 跨站请求伪造漏洞 — OSIsoft PI Web API 2017 | 8.8 | - | 2017-08-25 |
| CVE-2017-5187 | Micro Focus Enterprise Developer和Enterprise Server Directory Server 跨站请求伪造漏洞 — Micro Focus Enterprise Developer, Micro Focus Enterprise Server | 8.8 | - | 2017-08-21 |
| CVE-2017-7423 | Micro Focus Enterprise Developer和Enterprise Server 跨站请求伪造漏洞 — Micro Focus Enterprise Developer, Micro Focus Enterprise Server | 8.1 | - | 2017-08-21 |
| CVE-2017-7556 | Hawtio 跨站请求伪造漏洞 — hawtio | 8.1 | - | 2017-08-17 |
| CVE-2017-6756 | Cisco Prime Collaboration Provisioning tool 跨站请求伪造漏洞 — Cisco Prime Collaboration Provisioning Tool | 8.8 | - | 2017-08-07 |
| CVE-2017-6038 | Belden Hirschmann GECKO Lite Managed Switch 跨站请求伪造漏洞 — Belden Hirschmann GECKO | 8.1 | - | 2017-06-30 |
| CVE-2017-6042 | Sierra Wireless AirLink Raven XE和XT 跨站请求伪造漏洞 — Sierra Wireless AirLink Raven XE and XT | 8.8 | - | 2017-06-30 |
| CVE-2017-5244 | Rapid7 Metasploit Express、Community和Pro 跨站请求伪造漏洞 — Metasploit (Pro, Express, and Community editions) | 6.5 | - | 2017-06-15 |
| CVE-2017-7917 | 多款摩莎产品跨站请求伪造漏洞 — Moxa OnCell | 8.8 | - | 2017-05-29 |
| CVE-2017-6634 | Cisco Industrial Ethernet 1000 Series Switches 跨站请求伪造漏洞 — Cisco Industrial Ethernet 1000 Series Switches | 8.8 | - | 2017-05-22 |
| CVE-2017-2688 | Siemens RUGGEDCOM ROX I 跨站请求伪造漏洞 — RUGGEDCOM ROX I All versions | 8.8 | - | 2017-03-29 |
| CVE-2016-9127 | Revive Adserver 跨站请求伪造漏洞 — Revive Adserver All versions before 3.2.3 | 6.5 | - | 2017-03-28 |
| CVE-2016-9455 | Revive Adserver 跨站请求伪造漏洞 — Revive Adserver All versions before 3.2.3 | 8.8 | - | 2017-03-28 |
| CVE-2016-9456 | Revive Adserver 跨站请求伪造漏洞 — Revive Adserver All versions before 3.2.3 | 8.8 | - | 2017-03-28 |
| CVE-2017-2682 | Siemens RUGGEDCOM NMS 跨站请求伪造漏洞 — RUGGEDCOM NMS All versions < V2.1 (Windows and Linux) | 8.8 | - | 2017-02-27 |
| CVE-2014-2358 | Fox-IT Fox DataDiode应用程序跨站请求伪造漏洞 — DataDiode Appliance | 8.8 | - | 2014-10-19 |
| CVE-2014-2369 | 多款Omron产品跨站请求伪造漏洞 — NS15 | 8.0 | - | 2014-07-24 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4853 条 CVE 漏洞。