Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10249 1 Baijiacms Project 1 Baijiacms 2018-05-22 6.8 MEDIUM 8.8 HIGH
baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.
CVE-2018-10248 1 Wuzhicms 1 Wuzhi Cms 2018-05-21 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.
CVE-2018-10188 1 Phpmyadmin 1 Phpmyadmin 2018-05-21 6.8 MEDIUM 8.8 HIGH
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.
CVE-2018-10185 1 Tuzicms 1 Tuzicms 2018-05-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated by a history.pushState call.
CVE-2016-5809 1 Schneider-electric 6 Ion5000, Ion7300, Ion7500 and 3 more 2018-05-20 6.8 MEDIUM 8.8 HIGH
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.
CVE-2018-10117 1 Icmsdev 1 Icms 2018-05-18 6.8 MEDIUM 8.8 HIGH
An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP.
CVE-2018-10224 1 Yzmcms 1 Yzmcms 2018-05-17 6.0 MEDIUM 6.8 MEDIUM
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.
CVE-2018-10223 1 Yzmcms 1 Yzmcms 2018-05-17 6.0 MEDIUM 6.8 MEDIUM
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.
CVE-2015-0151 1 D-link 2 Dir-815, Dir-815 Firmware 2018-05-16 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVE-2018-1000153 1 Jenkins 1 Vsphere 2018-05-15 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java, PowerOff.java, PowerOn.java, Reconfigure.java, Rename.java, RenameSnapshot.java, RevertToSnapshot.java, SuspendVm.java, TakeSnapshot.java, VSphereBuildStepContainer.java, vSphereCloudProvisionedSlave.java, vSphereCloudSlave.java, vSphereCloudSlaveTemplate.java, VSphereConnectionConfig.java, vSphereStep.java that allows attackers to perform form validation related actions, including sending numerous requests to the configured vSphere server, potentially resulting in denial of service, or send credentials stored in Jenkins with known ID to an attacker-specified server ("test connection").
CVE-2018-6874 1 Auth0 1 Auth0.js 2018-05-15 6.8 MEDIUM 8.8 HIGH
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
CVE-2018-9856 1 Kotti Project 1 Kotti 2018-05-15 6.8 MEDIUM 8.8 HIGH
Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-document/@@share request.
CVE-2017-0362 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2018-05-15 6.8 MEDIUM 8.8 HIGH
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
CVE-2018-10127 1 Xyhcms Project 1 Xyhcms 2018-05-11 6.8 MEDIUM 8.8 HIGH
An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the administrator role.
CVE-2018-6934 1 Ordermanagementscript 1 Online Tutoring Script 2018-05-11 6.8 MEDIUM 8.8 HIGH
CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3.
CVE-2014-5072 1 Wpsecurityauditlog 1 Wp Security Audit Log 2018-05-09 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2018-8814 1 Wolfcms 1 Wolf Cms 2018-05-09 5.8 MEDIUM 6.5 MEDIUM
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request.
CVE-2014-5034 1 Fresh-media 1 Brute Force Login Protection 2018-05-09 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that have unknown impact via a crafted request to the brute-force-login-protection page to wp-admin/options-general.php.
CVE-2018-8908 1 Frog Cms Project 1 Frog Cms 2018-05-09 6.8 MEDIUM 8.8 HIGH
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.
CVE-2018-10048 1 Iscripts 1 Eswap 2018-05-09 6.8 MEDIUM 8.8 HIGH
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
CVE-2018-8893 1 Zblogcn 1 Z-blogphp 2018-05-01 6.8 MEDIUM 8.8 HIGH
Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.
CVE-2018-8972 1 Creditwestbank 1 Cwcms 2018-04-24 6.8 MEDIUM 8.8 HIGH
Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters.
CVE-2018-9134 1 Dedecms 1 Dedecms 2018-04-23 6.8 MEDIUM 8.8 HIGH
file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.
CVE-2015-2009 1 Ibm 1 Qradar Security Information And Event Manager 2018-04-23 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force ID: 103921.
CVE-2018-9108 1 Quickappscms 1 Quickapps Cms 2018-04-20 6.8 MEDIUM 8.8 HIGH
CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges.
CVE-2018-8764 2 Debian, Ldap-account-manager 2 Debian Linux, Ldap Account Manager 2018-04-20 6.8 MEDIUM 8.8 HIGH
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.
CVE-2014-0054 1 Springsource 1 Spring Framework 2018-04-20 6.8 MEDIUM N/A
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
CVE-2018-7700 1 Dedecms 1 Dedecms 2018-04-19 6.8 MEDIUM 8.8 HIGH
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
CVE-2018-1213 1 Dell 1 Emc Isilon Onefs 2018-04-19 6.8 MEDIUM 8.8 HIGH
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send unauthorized requests to the server on behalf of authenticated users of the application.
CVE-2014-2675 1 Wp-html-sitemap Project 1 Wp-html-sitemap 2018-04-18 5.8 MEDIUM 6.5 MEDIUM
Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in wp-admin/options-general.php.
CVE-2014-2274 1 Subscribe To Comments Reloaded Project 1 Subscribe To Comments Reloaded 2018-04-18 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/index.php page to wp-admin/admin.php.
CVE-2018-9923 1 Icmsdev 1 Icms 2018-04-17 6.8 MEDIUM 8.8 HIGH
An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request.
CVE-2014-1457 1 Openwebanalytics 1 Open Web Analytics 2018-04-17 6.8 MEDIUM 8.8 HIGH
Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.
CVE-2014-2550 1 Disable Comments 1 Disable Comments Project 2018-04-17 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php.
CVE-2018-10031 1 Cmsmadesimple 1 Cms Made Simple 2018-04-13 6.8 MEDIUM 8.8 HIGH
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
CVE-2018-10030 1 Cmsmadesimple 1 Cms Made Simple 2018-04-13 6.8 MEDIUM 8.8 HIGH
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
CVE-2017-17960 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2018-04-12 6.8 MEDIUM 8.8 HIGH
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
CVE-2018-1000137 1 I-librarian 1 I Librarian 2018-04-12 6.8 MEDIUM 8.8 HIGH
I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed without the administrator's knowledge.
CVE-2018-1000092 1 Cmsmadesimple 1 Cms Made Simple 2018-04-10 6.8 MEDIUM 8.8 HIGH
CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page. This vulnerability appears to have been fixed in 2.2.6.
CVE-2014-4613 1 Piwigo 1 Piwigo 2018-04-09 4.3 MEDIUM 6.5 MEDIUM
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.
CVE-2018-8717 1 Joyplus-cms Project 1 Joyplus-cms 2018-04-09 6.8 MEDIUM 8.8 HIGH
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.
CVE-2018-1000082 1 Ajenti 1 Ajenti 2018-04-06 6.8 MEDIUM 8.8 HIGH
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed..
CVE-2018-7701 1 Securenvoy 1 Securmail 2018-04-06 5.8 MEDIUM 6.5 MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) delete e-mail messages via a delete action in a request to secmail/getmessage.exe or (2) spoof arbitrary users and reply to their messages via a request to secserver/securectrl.exe.
CVE-2018-1000093 1 Cryptonote 1 Cryptonote 2018-04-05 6.8 MEDIUM 8.8 HIGH
CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the simplewallet RPC daemons will process any commands sent to them, resulting in remote command execution and a takeover of the cryptocurrency wallet if an attacker can trick an application such as a web browser into connecting and sending a command for example. This attack appears to be exploitable via a victim visiting a webpage hosting malicious content that trigger such behavior.
CVE-2018-6224 1 Trendmicro 1 Email Encryption Gateway 2018-04-04 6.8 MEDIUM 8.8 HIGH
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user browsing an attacker-controlled domain.
CVE-2018-7307 1 Auth0 1 Auth0.js 2018-03-28 6.8 MEDIUM 8.8 HIGH
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
CVE-2017-7641 1 Qnap 2 Media Streaming Add-on, Qts 2018-03-27 6.8 MEDIUM 8.8 HIGH
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
CVE-2018-7733 1 Yxtcmf 1 Yxtcmf 2018-03-26 6.8 MEDIUM 8.8 HIGH
An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/user/add_post.html.
CVE-2018-7565 1 Polycom 2 Qdx 6000, Qdx 6000 Firmware 2018-03-26 6.8 MEDIUM 8.8 HIGH
CSRF exists on Polycom QDX 6000 devices.
CVE-2016-0272 1 Ibm 1 Financial Transaction Manager 2018-03-26 6.0 MEDIUM 8.0 HIGH
Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID: 111052.