Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16560 1 Jenkins 1 Websphere Deployer 2020-01-03 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.
CVE-2019-6030 1 Custom Body Class Project 1 Custom Body Class 2020-01-03 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2019-16550 1 Jenkins 1 Maven 2020-01-03 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attacker specified web server and parse XML documents.
CVE-2018-1934 1 Ibm 1 Cognos Business Intelligence 2019-12-27 6.8 MEDIUM 8.8 HIGH
IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153179.
CVE-2019-17633 1 Eclipse 1 Che 2019-12-27 6.8 MEDIUM 8.8 HIGH
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.
CVE-2019-19832 1 Xerox 2 Altalink C8035, Altalink C8035 Firmware 2019-12-23 6.8 MEDIUM 8.8 HIGH
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
CVE-2019-13930 1 Siemens 1 Xhq 2019-12-19 5.8 MEDIUM 8.1 HIGH
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user, who must be authenticated to the web interface. A successful attack could allow an attacker to trigger actions via the web interface that the legitimate user is allowed to perform. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.
CVE-2019-16575 1 Jenkins 1 Alauda Kubernetes Support 2019-12-18 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins.
CVE-2019-11657 1 Microfocus 1 Arcsight Logger 2019-12-18 6.8 MEDIUM 8.8 HIGH
Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could be exploited to perform CSRF attack.
CVE-2019-16573 1 Jenkins 1 Alauda Devops Pipeline 2019-12-18 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2014-0197 1 Redhat 2 Cloudforms, Cloudforms Management Engine 2019-12-18 6.8 MEDIUM 8.8 HIGH
CFME: CSRF protection vulnerability via permissive check of the referrer header
CVE-2019-16565 1 Jenkins 1 Team Concert 2019-12-18 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-16570 1 Jenkins 1 Rapiddeploy 2019-12-18 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server.
CVE-2019-0398 1 Sap 1 Businessobjects Business Intelligence Platform 2019-12-17 6.8 MEDIUM 8.8 HIGH
Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request Forgery.
CVE-2015-7537 2 Jenkins, Redhat 2 Jenkins, Openshift 2019-12-17 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.
CVE-2019-19685 1 Nopcommerce 1 Nopcommerce 2019-12-17 6.8 MEDIUM 8.8 HIGH
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.
CVE-2019-18346 1 Davical 1 Davical 2019-12-14 6.8 MEDIUM 8.8 HIGH
A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.
CVE-2019-15934 1 Intesync 1 Solismed 2019-12-13 6.8 MEDIUM 8.8 HIGH
Intesync Solismed 3.3sp has CSRF.
CVE-2016-8673 1 Siemens 8 Simatic Cp 343-1, Simatic Cp 343-1 Firmware, Simatic Cp 443-1 and 5 more 2019-12-12 6.8 MEDIUM 8.8 HIGH
A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server at port 80/TCP or port 443/TCP of the affected devices could allow remote attackers to perform actions with the permissions of an authenticated user, provided the targeted user has an active session and is induced to trigger the malicious request.
CVE-2012-2079 1 Drupal 1 Activity 2019-12-11 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
CVE-2015-3140 1 Synametrics 3 Synaman, Syncrify, Syntail 2019-12-04 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567
CVE-2013-6811 1 D-link 2 Dsl6740u, Dsl6740u Firmware 2019-12-04 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding, (2) Port Triggering Entries, (3) URL Filters in Parental Control, (4) Print Server settings, (5) QoS Queue Setup, or (6) QoS Classification Entries.
CVE-2018-10503 1 Baijiacms Project 1 Baijiacms 2019-12-03 6.8 MEDIUM 8.8 HIGH
An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edituser, changing the administrator password via op=changepwd, or deleting an account via op=deleteuser.
CVE-2013-3312 1 Loftek 2 Nexus 543, Nexus 543 Firmware 2019-11-27 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi.
CVE-2019-19013 1 Pagekit 1 Pagekit 2019-11-27 6.8 MEDIUM 8.8 HIGH
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
CVE-2019-16548 1 Jenkins 1 Google Compute Engine 2019-11-22 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used to provision new agents.
CVE-2011-4952 1 Cobblerd 1 Cobbler 2019-11-21 6.8 MEDIUM 8.8 HIGH
cobbler: Web interface lacks CSRF protection when using Django framework
CVE-2019-16993 2 Debian, Phpbb 2 Debian Linux, Phpbb 2019-11-21 6.8 MEDIUM 8.8 HIGH
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
CVE-2019-18884 1 Fairsketch 1 Rise - Ultimate Project Manager 2019-11-19 6.8 MEDIUM 8.8 HIGH
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
CVE-2010-3305 1 Pixelpost 1 Pixelpost 2019-11-14 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
CVE-2013-6364 2 Debian, Horde 2 Debian Linux, Groupware 2019-11-13 6.8 MEDIUM 8.8 HIGH
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
CVE-2019-7273 1 Optergy 2 Enterprise, Proton 2019-11-12 6.8 MEDIUM 8.8 HIGH
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-7262 1 Nortekcontrol 4 Linear Emerge Elite, Linear Emerge Elite Firmware, Linear Emerge Essential and 1 more 2019-11-12 6.8 MEDIUM 8.8 HIGH
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
CVE-2019-17237 1 Getigniteup 1 Igniteup 2019-11-12 6.8 MEDIUM 8.8 HIGH
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
CVE-2019-10847 1 Computrols 1 Computrols Building Automation Software 2019-11-12 6.8 MEDIUM 8.8 HIGH
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
CVE-2019-18411 1 Zohocorp 1 Manageengine Adselfservice Plus 2019-11-08 6.8 MEDIUM 8.8 HIGH
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
CVE-2015-5395 2 Debian, Inverse 2 Debian Linux, Sogo 2019-11-07 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
CVE-2019-8109 1 Magento 1 Magento 2019-11-07 6.0 MEDIUM 8.0 HIGH
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.
CVE-2019-18650 1 Joomla 1 Joomla\! 2019-11-06 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
CVE-2019-17675 1 Wordpress 1 Wordpress 2019-11-05 6.8 MEDIUM 8.8 HIGH
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVE-2019-18206 1 Zucchetti 1 Infobusiness 2019-11-05 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
CVE-2019-9926 1 Labkey 1 Labkey Server 2019-11-01 6.8 MEDIUM 8.8 HIGH
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability.
CVE-2019-1010096 1 Domainmod 1 Domainmod 2019-10-30 6.8 MEDIUM 8.8 HIGH
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html page.
CVE-2019-1010095 1 Domainmod 1 Domainmod 2019-10-30 6.8 MEDIUM 8.8 HIGH
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After the administrator logged in, open the html page.
CVE-2010-4241 1 Tiki 1 Tikiwiki Cms\/groupware 2019-10-29 6.8 MEDIUM 8.8 HIGH
Tiki Wiki CMS Groupware 5.2 has CSRF
CVE-2013-4848 1 Tp-link 2 Tl-wdr4300, Tl-wdr4300 Firmware 2019-10-28 9.3 HIGH 8.8 HIGH
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
CVE-2019-18414 1 Sourcecodester 1 Restaurant Management System 2019-10-28 6.8 MEDIUM 8.8 HIGH
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a crafted HTML page.
CVE-2019-10462 1 Jenkins 1 Dynatrace Application Monitoring 2019-10-25 6.8 MEDIUM 8.1 HIGH
A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.
CVE-2019-6282 1 Chinamobileltd 2 Gpn2.4p21-c-cn, Gpn2.4p21-c-cn Firmware 2019-10-24 6.8 MEDIUM 8.8 HIGH
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
CVE-2019-10468 1 Jenkins 1 Kubernetes Ci 2019-10-24 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.