Threats Tagged 'cwe-352'
View all threats tagged with 'cwe-352'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-352'
Click on any threat for detailed analysis and mitigation recommendations
0 Adobe Experience Manager (AEM) 6.5 Forms JEE contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to bypass security features and gain unauthorized write access. Exploitation requires user interaction, such as visiting a malicious URL or interacting with a compromised webpage. This vulnerability can cause limited disruption to availability but does not impact confidentiality. Join the discussion | CVE Database V5 | 09/22/2026, 18:56:04 UTC Added: 09/22/2026, 19:03:33 UTC |
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is false, which affects self-hosted Docker and WAR deployments. An attacker can provide an authorization code for the attacker's cloud-storage identity and induce a victim to visit a callback URL, causing the victim's draw.io session to become authenticated as the attacker identity without a valid state binding. The shared handler affects Google Drive, OneDrive, GitHub, GitLab, and Dropbox integrations. The victim can then unknowingly perform cloud-storage actions under the attacker's identity, causing session integrity loss and misattribution, but the identity binding does not itself grant access to existing victim cloud files. This issue is fixed in version 30.2.7. Join the discussion | CVE Database V5 | 09/21/2026, 16:29:43 UTC Added: 09/21/2026, 16:47:18 UTC |
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Exploitation requires the victim to have completed an OAuth flow in the current session and the deployment to enable auth.google.enabled, auth.github.enabled, or the Slack integration. This issue is fixed in version 0.91.1. Join the discussion | CVE Database V5 | 09/21/2026, 15:45:27 UTC Added: 09/21/2026, 16:02:29 UTC |
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability. Join the discussion | CVE Database V5 | 09/20/2026, 06:00:18 UTC Added: 09/20/2026, 06:32:09 UTC |
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. Join the discussion | GCVE Database | 09/18/2026, 21:32:26 UTC Added: 09/19/2026, 01:26:58 UTC |
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability. Join the discussion | GCVE Database | 09/18/2026, 21:32:26 UTC Added: 09/19/2026, 01:26:57 UTC |
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. Join the discussion | CVE Database V5 | 09/18/2026, 15:38:37 UTC Added: 09/18/2026, 15:47:08 UTC |
CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an authenticated administrator to issue one of these requests without a validated session token, causing unintended resets of electronic download usage counters or deletion of stored customer payment-card tokens. This issue is fixed in version 6.7.5. Join the discussion | CVE Database V5 | 09/17/2026, 22:04:40 UTC Added: 09/17/2026, 22:17:57 UTC |
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the selected view to Flask-WTF's process-global exemption set. The is_token_authenticated() function in src/utils/token_auth.py calls extract_token_from_request() and treats any present token, including request.args.get('token'), as authenticated without hashing the token, querying the database, or checking validity. A network-reachable attacker can therefore send a false token to disable CSRF protection for the targeted view for the worker lifetime. Because the exemption applies to the view function across HTTP methods, a cross-origin GET to /account with a query token can poison CSRF state for a later state-changing POST without triggering CORS preflight. This browser sequence requires attacker-controlled content on a sibling subdomain under the documented cookie conditions. The bypass can modify profile data, custom prompts, transcription settings, preferences, and administrative status through routes such as admin_toggle_admin. The change_password route also skips current-password verification when current_user.password is empty, allowing the chain to set a local password on an SSO-only account and bypass SSO. This issue is fixed in version 0.8.21-alpha. Join the discussion | CVE Database V5 | 09/17/2026, 20:20:29 UTC Added: 09/17/2026, 20:47:35 UTC |
0 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. Join the discussion | CVE Database V5 | 09/17/2026, 13:40:34 UTC Added: 09/17/2026, 14:47:19 UTC |
Showing 1 to 10 of 1377 results