Vulnerabilities (CVE)

Filtered by CWE-352
Total 5731 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-5395 2 Alinto, Debian 2 Sogo, Debian Linux 2022-12-20 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
CVE-2022-46059 1 Aerocms Project 1 Aerocms 2022-12-16 N/A 6.5 MEDIUM
AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-46062 1 Gym Management System Project 1 Gym Management System 2022-12-15 N/A 4.5 MEDIUM
Gym Management System v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-46688 1 Jenkins 1 Sonar Gerrit 2022-12-14 N/A 6.5 MEDIUM
A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.
CVE-2022-45980 1 Tenda 2 Ax12, Ax12 Firmware 2022-12-14 N/A 8.8 HIGH
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
CVE-2019-4231 2 Ibm, Netapp 2 Cognos Analytics, Oncommand Insight 2022-12-14 4.3 MEDIUM 4.3 MEDIUM
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.
CVE-2016-8718 1 Moxa 2 Awk-3131a, Awk-3131a Firmware 2022-12-13 6.8 MEDIUM 8.8 HIGH
An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.
CVE-2022-45228 1 Dragino 2 Lg01 Lora, Lg01 Lora Firmware 2022-12-13 N/A 3.5 LOW
Dragino Lora LG01 18ed40 IoT v4.3.4 was discovered to contain a Cross-Site Request Forgery in the logout page.
CVE-2022-44849 1 Metinfo 1 Metinfo 2022-12-12 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.
CVE-2022-3024 1 Simple Bitcoin Faucets Project 1 Simple Bitcoin Faucets 2022-12-09 N/A 5.4 MEDIUM
The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
CVE-2019-4167 1 Ibm 1 Storediq 2022-12-09 4.3 MEDIUM 6.5 MEDIUM
IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158700.
CVE-2021-25095 1 Ip2location 1 Country Blocker 2022-12-09 5.5 MEDIUM 7.1 HIGH
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
CVE-2021-25032 1 Publishpress 1 Capabilities 2022-12-09 7.5 HIGH 9.8 CRITICAL
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.
CVE-2021-25097 1 Creativityjuice 1 Labtools 2022-12-09 4.0 MEDIUM 6.5 MEDIUM
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authenticated users, such as subscriber to delete arbitrary publication
CVE-2021-25025 1 Theeventscalendar 1 Eventcalendar 2022-12-09 4.0 MEDIUM 4.3 MEDIUM
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
CVE-2019-4117 1 Ibm 1 Cloud Private 2022-12-09 6.8 MEDIUM 8.8 HIGH
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158116.
CVE-2021-44227 2 Debian, Gnu 2 Debian Linux, Mailman 2022-12-09 6.8 MEDIUM 8.8 HIGH
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
CVE-2017-12126 1 Moxa 2 Edr-810, Edr-810 Firmware 2022-12-09 6.8 MEDIUM 8.8 HIGH
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forgery. An attacker can create malicious HTML to trigger this vulnerability.
CVE-2021-24431 1 Language Bar Flags Project 1 Language Bar Flags 2022-12-07 4.3 MEDIUM 4.3 MEDIUM
The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users
CVE-2019-4515 1 Ibm 1 Security Key Lifecycle Manager 2022-12-07 4.3 MEDIUM 6.5 MEDIUM
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 165137.