Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19135 1 Clippercms 1 Clippercms 2019-01-30 6.8 MEDIUM 8.8 HIGH
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.
CVE-2018-1000411 1 Jenkins 1 Junit 2019-01-28 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.
CVE-2017-17835 1 Apache 1 Airflow 2019-01-25 6.8 MEDIUM 8.8 HIGH
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
CVE-2019-6779 1 Chshcms 1 Cscms 2019-01-25 5.8 MEDIUM 8.1 HIGH
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
CVE-2019-6244 1 Usualtool 1 Usualtoolcms 2019-01-24 6.8 MEDIUM 8.8 HIGH
An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently execute arbitrary PHP code by writing that code into a .php file.
CVE-2018-20228 1 Subsonic 1 Subsonic 2019-01-24 6.0 MEDIUM 8.0 HIGH
Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.
CVE-2018-20576 1 Orange 2 Arv7519rw22 Livebox 2.1, Arv7519rw22 Livebox 2.1 Firmware 2019-01-23 5.8 MEDIUM 5.4 MEDIUM
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone number. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.
CVE-2019-6510 1 Creditease-sec 1 Insight 2019-01-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2019-6508 1 Creditease-sec 1 Insight 2019-01-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2019-6507 1 Creditease-sec 1 Insight 2019-01-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2019-6509 1 Creditease-sec 1 Insight 2019-01-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2018-20577 1 Orange 2 Arv7519rw22 Livebox 2.1, Arv7519rw22 Livebox 2.1 Firmware 2019-01-22 9.4 HIGH 9.1 CRITICAL
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.
CVE-2018-1000417 1 Jenkins 1 Email Extension Template 2019-01-22 5.8 MEDIUM 8.1 HIGH
A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing templates.
CVE-2018-1000414 1 Jenkins 1 Config File Provider 2019-01-22 5.8 MEDIUM 8.1 HIGH
A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file definitions.
CVE-2018-20728 1 Nedi 1 Nedi 2019-01-22 6.8 MEDIUM 8.8 HIGH
A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.
CVE-2016-10738 1 Castlamp 1 Zenbership 2019-01-18 6.8 MEDIUM 8.8 HIGH
Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
CVE-2019-6249 1 Hucart 1 Hucart 2019-01-16 6.8 MEDIUM 8.8 HIGH
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.
CVE-2019-6294 1 Easycms 1 Easycms 2019-01-16 6.8 MEDIUM 8.8 HIGH
An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI.
CVE-2018-20612 1 Asthis 1 Universal Website Asthis 2019-01-16 6.8 MEDIUM 8.8 HIGH
UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.
CVE-2018-19182 1 Engelsystem 1 Engelsystem 2019-01-14 6.8 MEDIUM 8.8 HIGH
Engelsystem before commit hash 2e28336 allows CSRF.
CVE-2018-20595 1 Hsweb 1 Hsweb 2019-01-14 6.8 MEDIUM 8.8 HIGH
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
CVE-2018-20419 1 Douco 1 Douphp 2019-01-11 6.8 MEDIUM 8.8 HIGH
DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.
CVE-2018-19923 1 Sales \& Company Management System Project 1 Sales \& Company Management System 2019-01-11 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
CVE-2018-20603 1 Lfdycms 1 Lei Feng Tv Cms 2019-01-10 6.8 MEDIUM 8.8 HIGH
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.
CVE-2018-20613 1 Temmoku Project 1 Temmoku 2019-01-10 6.8 MEDIUM 8.8 HIGH
TEMMOKU T1.09 Beta allows admin/user/add CSRF.
CVE-2018-18842 1 Zblogcn 1 Z-blogphp 2019-01-09 6.8 MEDIUM 8.8 HIGH
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.
CVE-2018-1000846 1 Freshdns Project 1 Freshdns 2019-01-08 6.8 MEDIUM 8.8 HIGH
FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API calls in index.php / class.manager.php that can result in Editing domains and zones with victim's privileges. This attack appear to be exploitable via Victim must open a website containing attacker's javascript. This vulnerability appears to have been fixed in 1.0.5 and later.
CVE-2014-5395 1 Huawei 4 E3236 Firmware, E3276 Firmware, E5180s-22 Firmware and 1 more 2019-01-08 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users for requests that (1) modify configurations, (2) send SMS messages, or have other unspecified impact via unknown vectors.
CVE-2018-20188 1 Thedaylightstudio 1 Fuel Cms 2019-01-07 6.8 MEDIUM 8.8 HIGH
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
CVE-2018-18921 1 Phpservermonitor 1 Php Server Monitor 2019-01-07 5.8 MEDIUM 6.5 MEDIUM
PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.
CVE-2018-20598 1 Ucms Project 1 Ucms 2019-01-04 6.8 MEDIUM 8.8 HIGH
UCMS 1.4.7 has ?do=user_addpost CSRF.
CVE-2018-2474 1 Sap 1 Fiori 2019-01-04 4.3 MEDIUM 6.5 MEDIUM
SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.
CVE-2018-15334 1 F5 1 Big-ip Access Policy Manager 2019-01-04 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication.
CVE-2018-8892 1 Blackberry 1 Unified Endpoint Manager 2019-01-03 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.
CVE-2018-20015 1 Yzmcms 1 Yzmcms 2019-01-03 6.8 MEDIUM 8.8 HIGH
YzmCMS v5.2 has admin/role/add.html CSRF.
CVE-2018-19560 1 Bagesoft 1 Bagecms 2018-12-31 9.3 HIGH 8.8 HIGH
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
CVE-2018-19621 1 Showdoc 1 Showdoc 2018-12-26 4.3 MEDIUM 6.5 MEDIUM
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
CVE-2018-14892 1 Zyxel 2 Nsa325 V2, Nsa325 V2 Firmware 2018-12-26 6.8 MEDIUM 8.8 HIGH
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms.
CVE-2018-16832 1 Xunfeng Project 1 Xunfeng 2018-12-20 4.3 MEDIUM 6.5 MEDIUM
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.
CVE-2018-19544 1 Jeecms 1 Jeecms 2018-12-19 4.3 MEDIUM 6.5 MEDIUM
JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.
CVE-2018-19545 1 Jeecms 1 Jeecms 2018-12-19 6.8 MEDIUM 8.8 HIGH
JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.
CVE-2018-19334 1 Google 1 Monorail 2018-12-18 4.3 MEDIUM 5.3 MEDIUM
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.
CVE-2018-10099 1 Google 1 Monorail 2018-12-18 4.3 MEDIUM 5.3 MEDIUM
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.
CVE-2018-19555 1 Tp4a 1 Teleport 2018-12-18 6.8 MEDIUM 8.8 HIGH
tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.
CVE-2018-18794 1 School Event Management System Project 1 School Event Management System 2018-12-18 6.8 MEDIUM 8.8 HIGH
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
CVE-2018-19327 1 Jtbc 1 Jtbc Php 2018-12-18 6.8 MEDIUM 8.8 HIGH
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.
CVE-2014-3896 1 Seeds 1 Acmailer 2018-12-18 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.
CVE-2018-18797 1 School Attendance Monitoring System Project 1 School Attendance Monitoring System 2018-12-18 6.8 MEDIUM 8.8 HIGH
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
CVE-2018-18799 1 School Attendance Monitoring System Project 1 School Attendance Monitoring System 2018-12-18 6.8 MEDIUM 8.8 HIGH
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
CVE-2018-19332 1 S-cms 1 S-cms 2018-12-18 6.8 MEDIUM 8.8 HIGH
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.