Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-10488 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a news article via a crafted request.
CVE-2020-10489 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted request.
CVE-2020-10492 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a crafted request.
CVE-2020-10487 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
CVE-2020-10498 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 6.5 MEDIUM
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
CVE-2020-10483 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.
CVE-2020-10484 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request.
CVE-2020-10482 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request.
CVE-2020-10486 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request.
CVE-2020-10485 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request.
CVE-2020-10481 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted request.
CVE-2020-10479 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/add-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new news article via a crafted request.
CVE-2020-10480 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request.
CVE-2020-10478 1 Chadhaajay 1 Phpkb 2020-03-26 4.3 MEDIUM 8.8 HIGH
CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.
CVE-2020-10671 1 Canon 2 Oce Colorwave 500, Oce Colorwave 500 Firmware 2020-03-23 6.8 MEDIUM 8.8 HIGH
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.
CVE-2019-12769 1 Solarwinds 1 Serv-u Managed File Transfer 2020-03-20 6.8 MEDIUM 8.8 HIGH
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
CVE-2018-21037 1 Intelliants 1 Subrion 2020-03-20 6.8 MEDIUM 8.8 HIGH
Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
CVE-2020-9346 1 Zohocorp 1 Manageengine Password Manager Pro 2020-03-20 6.8 MEDIUM 8.8 HIGH
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
CVE-2020-10568 1 Onthegosystems 1 Sitepress-multilingual-cms 2020-03-19 6.8 MEDIUM 8.8 HIGH
The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
CVE-2020-6585 1 Nagios 1 Nagios 2020-03-19 6.8 MEDIUM 8.8 HIGH
Nagios Log Server 2.1.3 has CSRF.
CVE-2020-4199 1 Ibm 1 Tivoli Netcool\/omnibus 2020-03-19 4.3 MEDIUM 4.3 MEDIUM
IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910.
CVE-2020-10241 1 Joomla 1 Joomla\! 2020-03-18 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
CVE-2019-13199 1 Kyocera 2 Ecosys M5526cdw, Ecosys M5526cdw Firmware 2020-03-18 4.3 MEDIUM 6.5 MEDIUM
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2019-13395 1 Netgear 2 Cg3700b, Cg3700b Firmware 2020-03-18 6.8 MEDIUM 8.8 HIGH
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.
CVE-2020-10540 1 Untis 1 Webuntis 2020-03-18 6.8 MEDIUM 8.8 HIGH
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
CVE-2019-17653 1 Fortinet 1 Fortisiem 2020-03-18 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.
CVE-2019-13170 1 Xerox 2 Phaser 3320, Phaser 3320 Firmware 2020-03-17 4.3 MEDIUM 6.5 MEDIUM
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2019-10673 1 Ultimatemember 1 Ultimate Member 2020-03-16 9.3 HIGH 8.8 HIGH
A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.
CVE-2019-4726 1 Ibm 1 Sterling B2b Integrator 2020-03-12 4.3 MEDIUM 4.3 MEDIUM
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363.
CVE-2020-6206 1 Sap 1 Cloud Platform Integration 2020-03-12 4.3 MEDIUM 4.3 MEDIUM
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.
CVE-2019-16107 1 Phpbb 1 Phpbb 2020-03-11 4.3 MEDIUM 4.3 MEDIUM
Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.
CVE-2020-2147 1 Jenkins 1 Mac 2020-03-09 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
CVE-2020-2141 1 Jenkins 1 P4 2020-03-09 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.
CVE-2015-9309 1 Flippercode 1 Google Map 2020-03-09 6.8 MEDIUM 8.8 HIGH
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
CVE-2015-9308 1 Flippercode 1 Google Map 2020-03-09 6.8 MEDIUM 8.8 HIGH
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
CVE-2015-9307 1 Flippercode 1 Google Map 2020-03-09 6.8 MEDIUM 8.8 HIGH
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
CVE-2019-12273 1 Outsystems 1 Outsystems 2020-03-06 4.3 MEDIUM 6.5 MEDIUM
** DISPUTED ** OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability exists.
CVE-2020-7988 1 Phpipam 1 Phpipam 2020-03-05 6.8 MEDIUM 8.8 HIGH
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.
CVE-2020-10057 1 Metalgenix 1 Genixcms 2020-03-05 6.8 MEDIUM 8.8 HIGH
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
CVE-2020-3148 1 Cisco 1 Prime Network Registrar 2020-03-05 4.3 MEDIUM 7.1 HIGH
A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections in the web-based interface. An attacker could exploit this vulnerability by persuading a targeted user, with an active administrative session on the affected device, to click a malicious link. A successful exploit could allow an attacker to change the device's configuration, which could include the ability to edit or create user accounts of any privilege level. Some changes to the device's configuration could negatively impact the availability of networking services for other devices on networks managed by CPNR.
CVE-2019-20487 1 Netgear 2 Wnr1000, Wnr1000 Firmware 2020-03-04 6.8 MEDIUM 8.8 HIGH
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI.
CVE-2015-1583 1 Atutor 1 Atutor 2020-03-04 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.
CVE-2020-5402 1 Cloudfoundry 2 Cf-deployment, User Account And Authentication 2020-03-03 6.8 MEDIUM 8.8 HIGH
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
CVE-2017-8848 1 Allen Disk Project 1 Allen Disk 2020-03-02 4.3 MEDIUM 6.5 MEDIUM
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
CVE-2015-5686 1 Puppet 1 Puppet Enterprise 2020-03-02 6.8 MEDIUM 8.8 HIGH
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.
CVE-2012-2629 1 Axous 1 Axous 2020-02-28 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to admin/administrators_add.php; or (2) conduct cross-site scripting (XSS) attacks via the page_title parameter to admin/content_pages_edit.php; the (3) category_name[] parameter to admin/products_category.php; the (4) site_name, (5) seo_title, or (6) meta_keywords parameter to admin/settings_siteinfo.php; the (7) company_name, (8) address1, (9) address2, (10) city, (11) state, (12) country, (13) author_first_name, (14) author_last_name, (15) author_email, (16) contact_first_name, (17) contact_last_name, (18) contact_email, (19) general_email, (20) general_phone, (21) general_fax, (22) sales_email, (23) sales_phone, (24) support_email, or (25) support_phone parameter to admin/settings_company.php; or the (26) system_email, (27) sender_name, (28) smtp_server, (29) smtp_username, (30) smtp_password, or (31) order_notice_email parameter to admin/settings_email.php.
CVE-2019-20480 1 Miele 2 Xgw 3000 Zigbee Gateway, Xgw 3000 Zigbee Gateway Firmware 2020-02-28 6.8 MEDIUM 8.8 HIGH
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.
CVE-2013-4227 1 Mozilla 1 Persona 2020-02-27 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.
CVE-2019-19987 1 Seling 1 Visual Access Manager 2020-02-27 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An attacker can exploit the vulnerability to abuse functionalities such as change password, add user, add privilege, and so on.
CVE-2020-6844 1 Topmanage 1 Olk Webstore 2020-02-27 6.8 MEDIUM 8.8 HIGH
In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.