Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-46028 1 Mblog Project 1 Mblog 2022-01-25 4.3 MEDIUM 4.3 MEDIUM
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
CVE-2022-0245 1 Livehelperchat 1 Livehelperchat 2022-01-24 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
CVE-2022-0231 1 Livehelperchat 1 Live Helper Chat 2022-01-21 4.3 MEDIUM 6.5 MEDIUM
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-0226 1 Livehelperchat 1 Live Helper Chat 2022-01-21 4.3 MEDIUM 4.3 MEDIUM
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-46080 1 Vehicle Service Management System Project 1 Vehicle Service Management System 2022-01-13 3.5 LOW 4.8 MEDIUM
A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to Stored Cross Site Scripting Vulnerability.
CVE-2020-29292 1 Iball 2 Wrd12en, Wrd12en Firmware 2022-01-10 4.3 MEDIUM 6.5 MEDIUM
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
CVE-2020-20943 1 Qibosoft 1 Qibosoft 2022-01-06 4.3 MEDIUM 4.3 MEDIUM
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.
CVE-2021-4162 1 Archivy Project 1 Archivy 2022-01-04 4.3 MEDIUM 4.3 MEDIUM
archivy is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-24852 1 Mousewheel Smooth Scroll Project 1 Mousewheel Smooth Scroll 2022-01-04 4.3 MEDIUM 6.5 MEDIUM
The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2020-15600 1 Cmsuno Project 1 Cmsuno 2022-01-04 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
CVE-2020-8615 1 Themeum 1 Tutor Lms 2022-01-01 2.6 LOW 6.5 MEDIUM
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
CVE-2021-43846 1 Nebulab 1 Solidus 2021-12-29 4.3 MEDIUM 4.3 MEDIUM
`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without their knowledge. Versions 3.1.5, 3.0.5, and 2.11.14 contain a patch for this issue. The patch adds CSRF token verification to the "Add to cart" action. Adding forgery protection to a form that missed it can have some side effects. Other CSRF protection strategies as well as a workaround involving modifcation to config/application.rb` are available. More details on these mitigations are available in the GitHub Security Advisory.
CVE-2021-43156 1 Projectworlds 1 Online Book Store Project In Php 2021-12-28 4.3 MEDIUM 6.5 MEDIUM
In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.
CVE-2021-43158 1 Projectworlds 1 Online Shopping System In Php 2021-12-28 4.3 MEDIUM 4.3 MEDIUM
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
CVE-2020-20595 1 Opms Project 1 Opms 2021-12-23 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
CVE-2021-26800 1 User Management System In Php Stored Procedure Project 1 User Management System In Php Stored Procedure 2021-12-21 4.3 MEDIUM 6.5 MEDIUM
Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account.
CVE-2021-4123 1 Livehelperchat 1 Live Helper Chat 2021-12-20 4.3 MEDIUM 6.5 MEDIUM
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-24818 1 Wp Limits Project 1 Wp Limits 2021-12-16 4.3 MEDIUM 4.3 MEDIUM
The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make a logged in admin change them, which could make the blog unstable by setting low values
CVE-2021-24795 1 Phoeniixx 1 Filter Portfolio Gallery 2021-12-16 4.3 MEDIUM 6.5 MEDIUM
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.
CVE-2021-24780 1 Single Post Exporter Project 1 Single Post Exporter 2021-12-15 4.3 MEDIUM 4.3 MEDIUM
The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and give access to the export feature to any role such as subscriber. Subscriber users would then be able to export an arbitrary post/page (such as private and password protected) via a direct URL
CVE-2021-44942 1 Glfusion 1 Glfusion 2021-12-15 4.3 MEDIUM 4.3 MEDIUM
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.
CVE-2021-24784 1 Wp Admin Logo Changer Project 1 Wp Admin Logo Changer 2021-12-15 4.3 MEDIUM 6.5 MEDIUM
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.
CVE-2021-4092 1 Yetiforce 1 Yetiforce Customer Relationship Management 2021-12-14 4.3 MEDIUM 4.3 MEDIUM
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4082 1 Pimcore 1 Pimcore 2021-12-13 4.3 MEDIUM 4.3 MEDIUM
pimcore is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4033 1 Kimai 1 Kimai 2 2021-12-13 4.3 MEDIUM 6.5 MEDIUM
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-24251 1 Strategy11 1 Business Directory Plugin - Easy Listing Directories 2021-12-08 4.3 MEDIUM 4.3 MEDIUM
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example)
CVE-2021-4049 1 Livehelperchat 1 Live Helper Chat 2021-12-08 4.3 MEDIUM 6.5 MEDIUM
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4005 1 Firefly-iii 1 Firefly Iii 2021-12-06 4.3 MEDIUM 4.3 MEDIUM
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3944 1 Bookstackapp 1 Bookstack 2021-12-04 4.0 MEDIUM 6.8 MEDIUM
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-24272 1 Codeinitiator 1 Fitness Calculators 2021-12-03 4.3 MEDIUM 4.3 MEDIUM
The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue
CVE-2021-3993 1 Showdoc 1 Showdoc 2021-12-02 4.3 MEDIUM 6.5 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4015 1 Firefly-iii 1 Firefly Iii 2021-12-02 4.3 MEDIUM 4.3 MEDIUM
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-24749 1 Kazencoders 1 Url Shortify 2021-11-29 4.3 MEDIUM 4.3 MEDIUM
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.
CVE-2021-20842 1 Ec-cube 1 Ec-cube 2021-11-27 4.3 MEDIUM 6.5 MEDIUM
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially crafted web page.
CVE-2021-41273 1 Pterodactyl 1 Panel 2021-11-24 4.3 MEDIUM 4.3 MEDIUM
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a test email and Generating a node auto-deployment token. At no point would any data be exposed to the malicious user, this would simply trigger email spam to an administrative user, or generate a single auto-deployment token unexpectedly. This token is not revealed to the malicious user, it is simply created unexpectedly in the system. This has been addressed in release `1.6.6`. Users may optionally manually apply the fixes released in v1.6.6 to patch their own systems.
CVE-2021-39198 1 Oroinc 1 Client Relationship Management 2021-11-23 5.8 MEDIUM 5.4 MEDIUM
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.
CVE-2021-3957 1 Kimai 1 Kimai 2 2021-11-23 4.3 MEDIUM 4.3 MEDIUM
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3976 1 Kimai 1 Kimai 2 2021-11-23 4.3 MEDIUM 6.5 MEDIUM
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3963 1 Kimai 1 Kimai 2 2021-11-23 4.3 MEDIUM 4.3 MEDIUM
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-24853 1 Qr Redirector Project 1 Qr Redirector 2021-11-19 4.3 MEDIUM 4.3 MEDIUM
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects
CVE-2021-24802 1 Gesundheit-bewegt 1 Colorful Categories 2021-11-19 4.3 MEDIUM 6.5 MEDIUM
The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack
CVE-2021-24776 1 Wp Performance Score Booster Project 1 Wp Performance Score Booster 2021-11-19 4.3 MEDIUM 4.3 MEDIUM
The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
CVE-2021-3683 1 Showdoc 1 Showdoc 2021-11-16 4.3 MEDIUM 6.5 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3775 1 Showdoc 1 Showdoc 2021-11-16 5.8 MEDIUM 5.4 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3776 1 Showdoc 1 Showdoc 2021-11-16 5.8 MEDIUM 5.4 MEDIUM
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3932 1 Area17 1 Twill 2021-11-16 4.3 MEDIUM 4.3 MEDIUM
twill is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3931 1 Snipeitapp 1 Snipe-it 2021-11-16 4.3 MEDIUM 4.3 MEDIUM
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3921 1 Firefly-iii 1 Firefly Iii 2021-11-16 4.3 MEDIUM 4.3 MEDIUM
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-40518 1 Airangel 10 Hsmx-app-100, Hsmx-app-1000, Hsmx-app-1000 Firmware and 7 more 2021-11-15 4.3 MEDIUM 6.5 MEDIUM
Airangel HSMX Gateway devices through 5.2.04 allow CSRF.
CVE-2021-24832 1 Wp Seo Redirect 301 Project 1 Wp Seo Redirect 301 2021-11-13 4.3 MEDIUM 4.3 MEDIUM
The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack