Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9018 1 Litecart 1 Litecart 2020-02-26 5.0 MEDIUM 5.3 MEDIUM
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
CVE-2012-5556 2 Drupal, Restful Web Services Project 2 Drupal, Restful Web Services 2020-02-26 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-2.0-alpha3 for Drupal allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.
CVE-2020-9394 1 Supsystic 1 Pricing Table By Supsystic 2020-02-26 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
CVE-2019-17590 1 Csrf Magic Project 1 Csrf Magic 2020-02-25 6.8 MEDIUM 8.8 HIGH
** DISPUTED ** The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social engineering, enticing them to click the link. Once the user/victim clicks the "try again" button, the attacker can take over the account and perform unintended actions on the victim's behalf. NOTE: A third-party maintainer has stated that this CVE is a false report. They state that the csrf_callback function is actually a callback function to the callers own handler for output. The function called can be changed via configuration to a custom callback to handle failed validation differently. They also stated that there is no way for an attacker to change tokens to make them valid from the client side. The only thing an attack can do is to pull the token out of the javascript, but that will always be possible and has nothing to do with the callback.
CVE-2019-14304 1 Ricoh 104 M 2700, M 2700 Firmware, M 2701 and 101 more 2020-02-25 6.8 MEDIUM 8.8 HIGH
Ricoh SP C250DN 1.06 devices allow CSRF.
CVE-2013-2109 1 Undolog 1 Wp Cleanfix 2020-02-24 6.8 MEDIUM 8.8 HIGH
WordPress plugin wp-cleanfix has Remote Code Execution
CVE-2019-19662 1 Maxum 1 Rumpus Ftp 2020-02-24 4.3 MEDIUM 6.5 MEDIUM
A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can Create and Delete accounts via RAPR/TriggerServerFunction.html.
CVE-2019-19664 1 Maxum 1 Rumpus Ftp 2020-02-24 5.8 MEDIUM 7.1 HIGH
A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server Web settings at RAPR/WebSettingsGeneralSet.html.
CVE-2020-9341 1 Auieo 1 Candidats 2020-02-24 6.8 MEDIUM 8.8 HIGH
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.
CVE-2020-3114 1 Cisco 1 Data Center Network Manager 2020-02-24 6.8 MEDIUM 8.8 HIGH
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link while having an active session on an affected device. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user.
CVE-2019-12246 1 Silverstripe 1 Silverstripe 2020-02-20 4.3 MEDIUM 4.3 MEDIUM
SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools.
CVE-2019-12437 1 Silverstripe 1 Silverstripe 2020-02-20 6.8 MEDIUM 8.8 HIGH
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
CVE-2020-5530 1 Realestateconnected 1 Easy Property Listings 2020-02-19 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2020-9266 1 Soplanning 1 Soplanning 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
CVE-2020-9267 1 Soplanning 1 Soplanning 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
CVE-2020-9270 1 Icehrm 1 Icehrm 2020-02-19 6.8 MEDIUM 8.8 HIGH
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
CVE-2020-9271 1 Icehrm 1 Icehrm 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
CVE-2013-4792 1 Prestashop 1 Prestashop 2020-02-18 3.5 LOW 5.5 MEDIUM
PrestaShop before 1.4.11 allows logout CSRF.
CVE-2013-2108 1 Undolog 1 Cleanfix 2020-02-18 4.3 MEDIUM 5.4 MEDIUM
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
CVE-2016-10945 1 Pagelines 1 Pagelines 2020-02-17 6.8 MEDIUM 8.8 HIGH
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
CVE-2020-2116 1 Jenkins 1 Pipeline Github Notify Step 2020-02-14 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2012-6721 1 Socialengine 1 Socialengine 2020-02-12 6.8 MEDIUM 6.3 MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4.
CVE-2014-2225 1 Ui 3 Airvision Controller, Mfi Controller, Unifi Controller 2020-02-12 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified impact via a request to api/add/wlanconf; change the guest (3) password, (4) authentication method, or (5) restricted subnets via a request to api/set/setting/guest_access; (6) block, (7) unblock, or (8) reconnect users by MAC address via a request to api/cmd/stamgr; change the syslog (9) server or (10) port via a request to api/set/setting/rsyslogd; (11) have unspecified impact via a request to api/set/setting/smtp; change the syslog (12) server, (13) port, or (14) authentication settings via a request to api/cmd/cfgmgr; or (15) change the Unifi Controller name via a request to api/set/setting/identity.
CVE-2019-10784 1 Phppgadmin Project 1 Phppgadmin 2020-02-12 9.3 HIGH 9.6 CRITICAL
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the server.
CVE-2013-3568 1 Cisco 2 Linksys Wrt110, Linksys Wrt110 Firmware 2020-02-12 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
CVE-2012-6297 1 Dd-wrt 1 Dd-wrt 2020-02-11 9.3 HIGH 8.8 HIGH
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
CVE-2019-19667 1 Maxum 1 Rumpus Ftp 2020-02-11 5.8 MEDIUM 5.4 MEDIUM
A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an attacker to whitelist or block any IP address via RAPR/BlockedClients.html.
CVE-2019-19666 1 Maxum 1 Rumpus Ftp 2020-02-11 4.3 MEDIUM 4.3 MEDIUM
A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can create/update event notices via RAPR/EventNoticesSet.html.
CVE-2019-19669 1 Maxum 1 Rumpus Ftp 2020-02-11 5.8 MEDIUM 6.5 MEDIUM
A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could allow an attacker to delete, create, and update the upload forms via RAPR/TriggerServerFunction.html.
CVE-2014-5288 1 Kemptechnologies 1 Load Master 2020-02-11 6.8 MEDIUM 8.8 HIGH
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
CVE-2019-19668 1 Maxum 1 Rumpus Ftp 2020-02-11 4.3 MEDIUM 4.3 MEDIUM
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.
CVE-2019-19659 1 Maxum 1 Rumpus 2020-02-11 6.8 MEDIUM 8.8 HIGH
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html.
CVE-2019-19660 1 Maxum 1 Rumpus 2020-02-11 4.3 MEDIUM 6.5 MEDIUM
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.
CVE-2019-19665 1 Maxum 1 Rumpus 2020-02-11 4.3 MEDIUM 6.5 MEDIUM
A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.html.
CVE-2019-20059 1 Mfscripts 1 Yetishare 2020-02-11 6.8 MEDIUM 8.8 HIGH
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. NOTE: this issue exists because of an incomplete fix for CVE-2019-19732.
CVE-2013-3366 1 Trendnet 2 Tew-812dru, Tew-812dru Firmware 2020-02-10 9.3 HIGH 8.8 HIGH
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
CVE-2008-6586 1 Utorrent 1 Utorrent Webui 2020-02-10 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests that force the download of arbitrary torrent files via the add-url action and (2) hijack the authentication of administrators for requests that modify the administrator account via the setsetting action.
CVE-2019-19663 1 Maxum 1 Rumpus 2020-02-10 5.8 MEDIUM 6.5 MEDIUM
A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders after exploiting it at RAPR/FolderSetsSet.html.
CVE-2011-1085 1 Smoothwall 1 Smoothwall Express 2020-02-10 6.8 MEDIUM 8.8 HIGH
CSRF vulnerability in Smoothwall Express 3.
CVE-2019-20401 1 Atlassian 1 Jira 2020-02-07 4.3 MEDIUM 6.5 MEDIUM
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
CVE-2020-8658 1 Bestwebsoft 1 Htaccess 2020-02-07 6.8 MEDIUM 8.8 HIGH
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.
CVE-2020-8425 1 Cups Easy \(purchase \& Inventory\) Project 1 Cups Easy \(purchase \& Inventory\) 2020-02-07 4.3 MEDIUM 6.5 MEDIUM
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
CVE-2011-0525 1 Batavi 1 Batavi 2020-02-07 6.8 MEDIUM 8.8 HIGH
Batavi before 1.0 has CSRF.
CVE-2020-8420 1 Joomla 1 Joomla\! 2020-02-07 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
CVE-2020-8419 1 Joomla 1 Joomla\! 2020-02-06 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
CVE-2020-8417 1 Codesnippets 1 Code Snippets 2020-02-06 6.8 MEDIUM 8.8 HIGH
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
CVE-2020-6849 1 Hutchhouse 1 Marketo Forms And Tracking 2020-02-06 6.8 MEDIUM 8.8 HIGH
The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
CVE-2019-4613 1 Ibm 1 Planning Analytics 2020-02-06 6.8 MEDIUM 8.8 HIGH
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.
CVE-2020-7210 1 Umbraco 1 Umbraco Cms 2020-02-06 4.3 MEDIUM 4.3 MEDIUM
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
CVE-2020-8505 1 Arox 1 School Management Software Php\/mysql 2020-02-05 4.3 MEDIUM 6.5 MEDIUM
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.