Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13920 1 Siemens 1 Sinema Remote Connect Server 2019-10-09 4.3 MEDIUM 4.3 MEDIUM
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web application are not protected against Cross Site Request Forgery (CSRF) attacks. The security vulnerability could be exploited by an attacker that is able to trigger requests of a logged-in user to the application. The vulnerability could allow switching the connectivity state of a user or a device. At the time of advisory publication no public exploitation of this security vulnerability was known.
CVE-2019-10304 1 Jenkins 1 Xebialabs Xl Deploy 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers to initiate a connection to an attacker-specified server.
CVE-2019-10292 1 Jenkins 1 Kmap 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers to initiate a connection to an attacker-specified server.
CVE-2019-1003012 2 Jenkins, Redhat 2 Blue Ocean, Openshift Container Platform 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-core-js/src/js/urlconfig.js, blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java, blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java, blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.
CVE-2019-1003017 1 Jenkins 1 Job Import 2019-10-09 2.6 LOW 5.3 MEDIUM
A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additional plugins necessary to load the imported job's configuration.
CVE-2019-1003022 1 Jenkins 1 Monitoring 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.
CVE-2019-10408 1 Jenkins 1 Project Inheritance 2019-10-09 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.
CVE-2019-10388 1 Jenkins 1 Relution Enterprise Appstore Publisher 2019-10-09 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.
CVE-2019-10359 1 Jenkins 1 M2release 2019-10-09 6.8 MEDIUM 6.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.
CVE-2019-10289 1 Jenkins 1 Netsparker Cloud Scan 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers to initiate a connection to an attacker-specified server.
CVE-2019-10278 1 Jenkins 1 Jenkins-reviewbot 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
CVE-2018-15401 1 Cisco 1 Hosted Collaboration Mediation Fulfillment 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system via a web browser and with the privileges of the user.
CVE-2018-15438 1 Cisco 1 Prime Collaboration Assurance 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to use a web browser to perform arbitrary actions with the privileges of the user on an affected system.
CVE-2018-0215 1 Cisco 1 Identity Services Engine 2019-10-09 6.8 MEDIUM 6.3 MEDIUM
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections on the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCuv32863.
CVE-2018-0146 1 Cisco 1 Data Center Analytics Framework 2019-10-09 5.8 MEDIUM 5.4 MEDIUM
A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by the affected application. An attacker could exploit this vulnerability by persuading a user of the affected application to click a malicious link. A successful exploit could allow the attacker to submit arbitrary requests and take unauthorized actions on behalf of the user. Cisco Bug IDs: CSCvg45114.
CVE-2018-0216 1 Cisco 1 Identity Services Engine 2019-10-09 5.8 MEDIUM 5.4 MEDIUM
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvf69805.
CVE-2017-2613 1 Jenkins 1 Jenkins 2019-10-09 5.8 MEDIUM 5.4 MEDIUM
jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrators' web browsers could be manipulated to create a large number of user records (SECURITY-406).
CVE-2016-7067 1 Mmonit 1 Monit 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.
CVE-2018-17789 1 Prospecta 1 Master Data Online 2019-09-30 4.3 MEDIUM 6.5 MEDIUM
Prospecta Master Data Online (MDO) allows CSRF.
CVE-2019-12922 1 Phpmyadmin 1 Phpmyadmin 2019-09-28 5.8 MEDIUM 6.5 MEDIUM
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
CVE-2015-9418 1 Kibokolabs 1 Watupro 2019-09-27 5.8 MEDIUM 4.3 MEDIUM
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
CVE-2015-9440 1 Monetize Project 1 Monetize 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.
CVE-2015-9441 1 Bookmarkify Project 1 Bookmarkify 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.
CVE-2015-9442 1 Avenirsoft 1 Directdownload 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.
CVE-2015-9443 1 Wp Accurate Form Data Project 1 Wp Accurate Form Data 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.
CVE-2015-9447 1 Unitegallery 1 Unite Gallery Lite 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
CVE-2015-9413 1 Eshop Project 1 Eshop 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
CVE-2015-9417 1 Slidervilla 1 Testimonial Slider 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
CVE-2015-9422 1 Simplysymphony 1 Plugnedit 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.
CVE-2015-9421 1 Olevmedia 1 Olevmedia Shortcodes 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
CVE-2015-9433 1 Wp Social Bookmarking Light Project 1 Wp Social Bookmarking Light 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php.
CVE-2015-9431 1 Qtranslate X Project 1 Qtranslate X 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.
CVE-2015-9432 1 Thealpinepress 1 Alpine-photo-tile-for-instagram 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
CVE-2015-9428 1 Wplegalpages 1 Wp Legal Pages 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.
CVE-2015-9425 1 Byonepress 1 Social Locker 2019-09-26 4.3 MEDIUM 5.4 MEDIUM
The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.
CVE-2015-9424 1 Doc4design 1 Multicons 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
CVE-2015-9429 1 Yithemes 1 Yith Maintenance Mode 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.
CVE-2015-9427 1 Googmonify Project 1 Googmonify 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter.
CVE-2015-9409 1 Alo-easymail Project 1 Alo-easymail 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
CVE-2015-9437 1 Qurl 1 Dynamic Widgets 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.
CVE-2015-9434 1 Kiwi-logo-carousel Project 1 Kiwi-logo-carousel 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.
CVE-2019-16677 1 Idreamsoft 1 Icms 2019-09-23 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
CVE-2019-16721 1 5none 1 Nonecms 2019-09-23 5.8 MEDIUM 6.5 MEDIUM
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
CVE-2015-9388 1 Mtouch Quiz Project 1 Mtouch Quiz 2019-09-23 4.3 MEDIUM 6.5 MEDIUM
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
CVE-2015-9387 1 Mtouch Quiz Project 1 Mtouch Quiz 2019-09-23 4.3 MEDIUM 6.5 MEDIUM
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.
CVE-2019-16678 1 Yzmcms 1 Yzmcms 2019-09-23 4.3 MEDIUM 6.5 MEDIUM
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
CVE-2015-9408 1 Cyberseo 1 Xpinner Lite 2019-09-20 4.3 MEDIUM 6.5 MEDIUM
The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.
CVE-2016-10997 1 Yourinspirationweb 1 Beauty-premium 2019-09-20 4.3 MEDIUM 6.5 MEDIUM
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.
CVE-2019-10176 1 Redhat 1 Openshift Container Platform 2019-09-17 5.8 MEDIUM 5.4 MEDIUM
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
CVE-2019-14998 1 Atlassian 1 Jira 2019-09-16 4.3 MEDIUM 6.5 MEDIUM
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.