Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7906 1 Abb 2 Ip Gateway, Ip Gateway Firmware 2019-10-09 6.8 MEDIUM 8.8 HIGH
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.
CVE-2017-7423 1 Microfocus 2 Enterprise Developer, Enterprise Server 2019-10-09 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured. This includes creating new privileged credentials, resulting in privilege elevation (CWE-275). Note esfadmingui is not enabled by default.
CVE-2017-6038 1 Belden Hirschmann 2 Gecko Lite Managed Switch, Gecko Lite Managed Switch Firmware 2019-10-09 5.8 MEDIUM 7.1 HIGH
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.
CVE-2017-5263 1 Cambiumnetworks 10 Cnpilot E400, Cnpilot E400 Firmware, Cnpilot E410 and 7 more 2019-10-09 5.4 MEDIUM 8.0 HIGH
Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.
CVE-2017-5187 1 Microfocus 4 Directory Server, Enterprise Developer, Enterprise Server and 1 more 2019-10-09 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter (CWE-275) configuration information and inject OS commands (CWE-78) via forged requests.
CVE-2017-6042 1 Sierra Wireless 4 Airlink Raven Xe, Airlink Raven Xe Firmware, Airlink Raven Xt and 1 more 2019-10-09 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an unintentional request to the web server that will be treated as an authentic request.
CVE-2017-3187 1 Dotcms 1 Dotcms 2019-10-09 6.8 MEDIUM 8.8 HIGH
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request. An unauthenticated remote attacker may perform actions with the dotCMS administrator panel with the same permissions of a victim user or execute arbitrary system commands with the permissions of the user running the dotCMS application.
CVE-2017-3965 1 Mcafee 1 Network Security Manager 2019-10-09 6.8 MEDIUM 8.8 HIGH
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.
CVE-2017-14011 1 Prominent 2 Multiflex M10a Controller, Multiflex M10a Controller Firmware 2019-10-09 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site request forgery. This may allow an attacker to execute unauthorized code, resulting in changes to the configuration of the device.
CVE-2017-14362 1 Microfocus 1 Project And Portfolio Management 2019-10-09 6.8 MEDIUM 7.3 HIGH
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack.
CVE-2017-12271 1 Cisco 4 Spa300 Series Ip Phone, Spa300 Series Ip Phone Firmware, Spa500 Series Ip Phone and 1 more 2019-10-09 6.8 MEDIUM 8.8 HIGH
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308.
CVE-2017-12253 1 Cisco 1 Unified Intelligence Center 2019-10-09 6.8 MEDIUM 8.8 HIGH
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCve76872.
CVE-2017-0933 1 Ubnt 1 Edgeos 2019-10-09 8.5 HIGH 8.0 HIGH
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attacker with access to an operator (read-only) account could lure an admin (root) user to access the attacker-controlled page, allowing the attacker to gain admin privileges in the system.
CVE-2016-9127 1 Revive-adserver 1 Revive Adserver 2019-10-09 6.8 MEDIUM 8.8 HIGH
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery emails to the registered users, especially in conjunction with a bug that caused recovery emails to be sent to all the users at once. Both issues have been fixed.
CVE-2016-6557 1 Asus 14 Ea-n66, Ea-n66 Firmware, Rp-ac52 and 11 more 2019-10-09 6.8 MEDIUM 8.8 HIGH
In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
CVE-2016-1261 1 Juniper 1 Junos 2019-10-09 6.8 MEDIUM 8.8 HIGH
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).
CVE-2016-10529 1 Droppy Project 1 Droppy 2019-10-09 6.8 MEDIUM 8.8 HIGH
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new admin account under his control and delete others.
CVE-2016-10522 1 Rails Admin Project 1 Rails Admin 2019-10-09 6.8 MEDIUM 8.8 HIGH
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
CVE-2014-0594 1 Opensuse 1 Open Build Service 2019-10-09 6.8 MEDIUM 8.8 HIGH
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
CVE-2018-10233 1 Ultimatemember 1 User Profile \& Membership 2019-10-06 6.8 MEDIUM 8.8 HIGH
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.
CVE-2019-15040 1 Jetbrains 1 Youtrack 2019-10-03 6.8 MEDIUM 8.8 HIGH
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
CVE-2017-9062 2 Debian, Wordpress 2 Debian Linux, Wordpress 2019-10-03 5.0 MEDIUM 8.6 HIGH
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
CVE-2017-9810 1 Kaspersky 1 Anti-virus For Linux Server 2019-10-03 6.8 MEDIUM 8.8 HIGH
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
CVE-2017-8928 1 Mailcow 1 Mailcow\ 2019-10-02 6.8 MEDIUM 8.8 HIGH
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
CVE-2015-5007 1 Ibm 1 Websphere Commerce 2019-09-30 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVE-2016-2863 1 Ibm 1 Websphere Commerce 2019-09-30 6.0 MEDIUM 8.0 HIGH
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVE-2015-0970 1 Searchblox 1 Searchblox 2019-09-27 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users.
CVE-2015-9445 1 Unitegallery 1 Unite Gallery Lite 2019-09-26 6.8 MEDIUM 8.8 HIGH
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
CVE-2018-17792 1 Altn 1 Mdaemon Webmail 2019-09-26 6.8 MEDIUM 8.8 HIGH
MDaemon Webmail (formerly WorldClient) has CSRF.
CVE-2019-16706 1 Kkcms Project 1 Kkcms 2019-09-23 6.8 MEDIUM 8.8 HIGH
kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php.
CVE-2019-16658 1 Tuzicms 1 Tuzicms 2019-09-23 6.8 MEDIUM 8.8 HIGH
TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
CVE-2019-16659 1 Tuzicms 1 Tuzicms 2019-09-23 6.8 MEDIUM 8.8 HIGH
TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
CVE-2018-16380 1 Digimute 1 Ogma Cms 2019-09-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account.
CVE-2019-16660 1 Joyplus Project 1 Joyplus 2019-09-23 6.8 MEDIUM 8.8 HIGH
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
CVE-2015-9394 1 Usersultra 1 Users Ultra Membership 2019-09-20 6.8 MEDIUM 8.8 HIGH
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
CVE-2019-15089 1 Prise 1 Adas 2019-09-20 6.8 MEDIUM 8.8 HIGH
An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator.
CVE-2019-16531 1 Layerbb 1 Layerbb 2019-09-20 6.8 MEDIUM 8.8 HIGH
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
CVE-2016-10989 1 Leenk 1 Leenk.me 2019-09-17 6.8 MEDIUM 8.8 HIGH
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
CVE-2016-10974 1 Tonjoostudio 1 Fluid-responsive-slideshow 2019-09-17 6.8 MEDIUM 8.8 HIGH
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
CVE-2016-10978 1 Fossura 1 Tag Miner 2019-09-17 6.8 MEDIUM 8.8 HIGH
The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.
CVE-2016-10982 1 Kentothemes 1 Kento-post-view-counter 2019-09-17 6.8 MEDIUM 8.8 HIGH
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
CVE-2019-5993 1 Tipsandtricks-hq 1 Category Specific Rss Feed Subscription 2019-09-16 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2019-16311 1 Niushop 1 Niushop 2019-09-16 6.8 MEDIUM 8.8 HIGH
NIUSHOP V1.11 has CSRF via search&#95;info to index.php.
CVE-2019-5986 2 Ntt-east, Ntt-west 92 Pr-400ki, Pr-400ki Firmware, Pr-400mi and 89 more 2019-09-16 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, RS-500KI firmware version Ver.01.00.0070 and earlier, PR-500MI/RT-500MI firmware version Ver.01.01.0014 and earlier, and RS-500MI firmware version Ver.03.01.0019 and earlier, and Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI firmware version Ver.19.01.0005 and earlier, PR-S300SE/RT-S300SE/RV-S340SE firmware version Ver.19.40 and earlier, PR-400NE/RT-400NE/RV-440NE firmware version Ver.7.42 and earlier, PR-400KI/RT-400KI/RV-440KI firmware version Ver.07.00.1010 and earlier, PR-400MI/RT-400MI/RV-440MI firmware version Ver. 07.00.1012 and earlier, PR-500KI/RT-500KI firmware version Ver.01.00.0090 and earlier, and PR-500MI/RT-500MI firmware version Ver.01.01.0011 and earlier) allow remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2016-10946 1 Wp-d3 Project 1 Wp-d3 2019-09-13 6.8 MEDIUM 8.8 HIGH
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
CVE-2016-10944 1 Wpmaz 1 Multisite Post Duplicator 2019-09-13 6.8 MEDIUM 8.8 HIGH
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
CVE-2019-5992 1 Ultra-prod 1 Wordpress Ultra Simple Paypal Shopping Cart 2019-09-13 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2019-1259 1 Microsoft 1 Sharepoint Foundation 2019-09-12 6.8 MEDIUM 8.8 HIGH
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1261.
CVE-2019-1261 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2019-09-12 6.8 MEDIUM 8.8 HIGH
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1259.
CVE-2017-18607 1 Theme-fusion 1 Avada 2019-09-10 6.8 MEDIUM 8.8 HIGH
The avada theme before 5.1.5 for WordPress has CSRF.