Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16570 1 Keystonejs 1 Keystone 2018-01-31 6.8 MEDIUM 8.8 HIGH
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.
CVE-2016-0335 1 Ibm 1 Security Identity Manager 2018-01-29 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736.
CVE-2018-5368 1 Srbtranslatin Project 1 Srbtranslatin 2018-01-29 6.8 MEDIUM 8.8 HIGH
The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.
CVE-2018-5285 1 Wpscoop 1 Imageinject 2018-01-29 6.8 MEDIUM 8.8 HIGH
The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php.
CVE-2018-5658 1 Responsive Coming Soon Page Project 1 Responsive Coming Soon Page 2018-01-25 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.
CVE-2018-5656 1 Weblizar 1 Pinterest-feeds 2018-01-24 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.
CVE-2018-5669 1 Read And Understood Project 1 Read And Understood 2018-01-23 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php.
CVE-2012-0317 1 Sixapart 1 Movable Type 2018-01-18 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to hijack the authentication of arbitrary users for requests that modify data via the (1) commenting feature or (2) community script.
CVE-2011-4140 1 Djangoproject 1 Django 2018-01-18 6.8 MEDIUM N/A
The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged requests via vectors involving a DNS CNAME record and a web page containing JavaScript code.
CVE-2017-1000432 1 Vanillaforums 1 Vanilla Forums 2018-01-17 6.0 MEDIUM 8.0 HIGH
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
CVE-2018-5073 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-01-17 6.0 MEDIUM 6.8 MEDIUM
Online Ticket Booking has CSRF via admin/movieedit.php.
CVE-2017-1672 1 Ibm 1 Security Key Lifecycle Manager 2018-01-16 6.8 MEDIUM 8.8 HIGH
IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639.
CVE-2014-0120 2 Hawt, Redhat 2 Hawtio, Jboss Fuse 2018-01-11 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."
CVE-2012-0453 1 Mozilla 1 Bugzilla 2018-01-11 5.1 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows remote attackers to hijack the authentication of arbitrary users for requests that modify the product's installation via the XML-RPC API.
CVE-2017-17905 1 Car Rental Script Project 1 Car Rental Script 2018-01-10 6.8 MEDIUM 8.8 HIGH
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.
CVE-2017-17908 1 Responsive Realestate Script Project 1 Responsive Realestate Script 2018-01-10 6.8 MEDIUM 8.8 HIGH
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
CVE-2017-17936 1 Vanguard Project 1 Marketplace Digital Products Php 2018-01-10 6.8 MEDIUM 8.8 HIGH
Vanguard Marketplace Digital Products PHP has CSRF via /search.
CVE-2017-17930 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 6.8 MEDIUM 8.8 HIGH
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.
CVE-2012-1843 2 Dell, Quantum 7 Powervault Ml6000, Powervault Ml6000 Firmware, Powervault Ml6010 and 4 more 2018-01-10 6.0 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to hijack the authentication of users for requests that execute Linux commands via the fileName parameter, related to a "command-injection vulnerability."
CVE-2011-1397 1 Ibm 6 Maximo Asset Management, Maximo Asset Management Essentials, Maximo Service Desk and 3 more 2018-01-10 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote attackers to hijack the authentication of arbitrary users.
CVE-2017-17982 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 6.0 MEDIUM 6.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
CVE-2017-17939 1 Single Theater Booking Script Project 1 Single Theater Booking Script 2018-01-09 6.8 MEDIUM 8.8 HIGH
PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.
CVE-2017-17903 1 Fortunescripts 1 Lynda Clone 2018-01-09 6.8 MEDIUM 8.8 HIGH
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
CVE-2017-17891 1 Readymade Video Sharing Script Project 1 Readymade Video Sharing Script 2018-01-09 6.8 MEDIUM 8.8 HIGH
Readymade Video Sharing Script has CSRF via user-profile-edit.php.
CVE-2017-17894 1 Basic Job Site Script Project 1 Basic Job Site Script 2018-01-09 6.8 MEDIUM 8.8 HIGH
Readymade Job Site Script has CSRF via the /job URI.
CVE-2017-17990 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 6.8 MEDIUM 8.8 HIGH
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.
CVE-2017-1746 1 Ibm 1 Jazz For Service Management 2018-01-05 6.8 MEDIUM 8.8 HIGH
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.
CVE-2017-1631 1 Ibm 1 Jazz For Service Management 2018-01-05 6.8 MEDIUM 8.8 HIGH
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133140.
CVE-2012-0235 1 Advantech 1 Advantech Webaccess 2018-01-05 6.0 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2017-17774 1 Piwigo 1 Piwigo 2018-01-04 6.8 MEDIUM 8.8 HIGH
admin/configuration.php in Piwigo 2.9.2 has CSRF.
CVE-2017-17827 1 Piwigo 1 Piwigo 2018-01-03 6.8 MEDIUM 8.8 HIGH
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
CVE-2017-17830 1 Doditsolutions 1 Bus Booking Script 2018-01-03 6.0 MEDIUM 6.8 MEDIUM
Bus Booking Script has CSRF via admin/new_master.php.
CVE-2014-0831 1 Ibm 1 Financial Transaction Manager 2018-01-03 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.
CVE-2012-2341 2 Drupal, Rahul Singla 2 Drupal, Take Control 2017-12-29 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.
CVE-2012-1985 1 Realnetworks 2 Helix Mobile Server, Helix Server 2017-12-29 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hijack the authentication of administrators for requests that cause a denial of service (stack consumption and daemon crash) via a malformed URL.
CVE-2017-14092 1 Trendmicro 1 Scanmail 2017-12-26 6.8 MEDIUM 8.8 HIGH
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
CVE-2017-17056 1 Zkteco 1 Zktime Web 2017-12-20 6.8 MEDIUM 8.8 HIGH
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_password1, and new_password2 parameters to the /accounts/password_change/ URI. An attacker takes advantage of this scenario and creates a crafted CSRF link to add himself as an administrator to the ZKTime Web Software. He then uses social engineering methods to trick the administrator into clicking the forged HTTP request. The request is executed and the attacker becomes the Administrator of the ZKTime Web Software. If the vulnerability is successfully exploited, then an attacker (who would be a normal user of the web application) can escalate his privileges and become the administrator of ZKTime Web Software.
CVE-2016-10701 1 Hitachivantara 1 Pentaho Business Analytics 2017-12-17 6.8 MEDIUM 8.8 HIGH
In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.
CVE-2012-1936 1 Wordpress 1 Wordpress 2017-12-14 6.8 MEDIUM N/A
** DISPUTED ** The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user account instead of a user session, which might make it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks on specific actions and objects by sniffing the network, as demonstrated by attacks against the wp-admin/admin-ajax.php and wp-admin/user-new.php scripts. NOTE: the vendor reportedly disputes the significance of this issue because wp_create_nonce operates as intended, even if it is arguably inconsistent with certain CSRF protection details advocated by external organizations.
CVE-2012-2397 1 Owncloud 1 Owncloud 2017-12-13 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in ownCloud before 3.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences via vectors involving contacts.
CVE-2017-8138 1 Huawei 1 Hedex Lite 2017-12-08 6.8 MEDIUM 8.8 HIGH
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal services.
CVE-2017-1000224 1 Embedplus 1 Youtube 2017-12-03 4.3 MEDIUM 6.5 MEDIUM
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
CVE-2017-7851 1 D-link 1 Dcs-936l 2017-12-03 6.8 MEDIUM 8.8 HIGH
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.
CVE-2017-15516 1 Netapp 1 Snapcenter Server 2017-12-02 6.8 MEDIUM 8.8 HIGH
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated action in the user interface.
CVE-2017-11876 1 Microsoft 2 Project Server, Sharepoint Enterprise Server 2017-11-30 6.8 MEDIUM 8.8 HIGH
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser of the victim, aka "Microsoft Project Server Elevation of Privilege Vulnerability".
CVE-2017-16565 1 Grandstream 2 Ht802, Ht802 Firmware 2017-11-27 6.8 MEDIUM 8.8 HIGH
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.
CVE-2017-16563 1 Grandstream 2 Ht802, Ht802 Firmware 2017-11-27 6.0 MEDIUM 8.0 HIGH
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.
CVE-2017-1300 1 Ibm 1 Openpages Grc Platform 2017-11-25 6.8 MEDIUM 8.8 HIGH
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162.
CVE-2016-5372 1 Netapp 1 Snap Creator Framework 2017-11-16 6.8 MEDIUM 6.3 MEDIUM
Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
CVE-2017-1000147 1 Mahara 1 Mahara 2017-11-15 6.0 MEDIUM 6.8 MEDIUM
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading malicious files into their Mahara account.