Vulnerabilities (CVE)

Filtered by CWE-352
Total 5731 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24458 1 Jenkins 1 Bearychat 2023-02-02 N/A 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified URL.
CVE-2023-24446 1 Jenkins 1 Openid 2023-02-02 N/A 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the attacker's account.
CVE-2023-24447 1 Jenkins 1 Rabbitmq Consumer 2023-02-02 N/A 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password.
CVE-2023-24437 1 Jenkins 1 Jira Pipeline Steps 2023-02-02 N/A 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-19833 1 Tautulli 1 Tautulli 2023-02-01 4.3 MEDIUM 6.5 MEDIUM
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a user login area).
CVE-2019-14304 1 Ricoh 104 M 2700, M 2700 Firmware, M 2701 and 101 more 2023-02-01 6.8 MEDIUM 8.8 HIGH
Ricoh SP C250DN 1.06 devices allow CSRF.
CVE-2020-7991 1 Adive 1 Framework 2023-01-31 6.8 MEDIUM 8.8 HIGH
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
CVE-2022-28892 1 Mahara 1 Mahara 2023-01-30 6.8 MEDIUM 8.8 HIGH
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
CVE-2019-4142 1 Ibm 1 Cloud Private 2023-01-30 6.8 MEDIUM 8.8 HIGH
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338.
CVE-2022-46074 1 Helmet Store Showroom Project 1 Helmet Store Showroom 2023-01-30 N/A 8.8 HIGH
Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.
CVE-2023-0438 1 Modoboa 1 Modoboa 2023-01-30 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0406 1 Modoboa 1 Modoboa 2023-01-27 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0398 1 Modoboa 1 Modoboa 2023-01-27 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-22286 1 Ate-mahoroba 6 Maho-pbx Netdevancer, Maho-pbx Netdevancer Firmware, Maho-pbx Netdevancer Mobilegate and 3 more 2023-01-24 N/A 8.1 HIGH
Cross-site request forgery (CSRF) vulnerability in MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allows a remote unauthenticated attacker to hijack the user authentication and conduct user's unintended operations by having a user to view a malicious page while logged in.
CVE-2018-18772 1 Control-webpanel 1 Webpanel 2023-01-24 6.8 MEDIUM 8.8 HIGH
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.
CVE-2019-13477 1 Control-webpanel 1 Webpanel 2023-01-24 4.3 MEDIUM 8.8 HIGH
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
CVE-2018-18773 1 Control-webpanel 1 Webpanel 2023-01-24 6.8 MEDIUM 8.8 HIGH
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.
CVE-2023-22852 1 Tiki 1 Tiki 2023-01-23 N/A 6.5 MEDIUM
Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.
CVE-2022-23685 1 Arubanetworks 1 Clearpass Policy Manager 2023-01-23 N/A 8.8 HIGH
A vulnerability in the ClearPass Policy Manager web-based management interface exists which exposes some endpoints to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against these endpoints if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address this security vulnerability.
CVE-2020-12781 1 Combodo 1 Itop 2023-01-20 6.8 MEDIUM 8.8 HIGH
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.