Vulnerabilities (CVE)

Filtered by CWE-352
Total 5731 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36577 1 Jizhicms 1 Jizhicms 2022-08-22 N/A 8.8 HIGH
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
CVE-2022-36579 1 Wellcms 1 Wellcms 2022-08-22 N/A 8.8 HIGH
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-36224 1 Xunruicms 1 Xunruicms 2022-08-22 N/A 8.8 HIGH
XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2020-10504 1 Chadhaajay 1 Phpkb 2022-08-19 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.
CVE-2021-46426 1 Phpipam 1 Phpipam 2022-08-19 4.3 MEDIUM 6.1 MEDIUM
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
CVE-2022-23765 1 Iptime 6 Nas1dual, Nas1dual Firmware, Nas2dual and 3 more 2022-08-19 N/A 8.8 HIGH
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.
CVE-2022-36312 1 Airspan 2 Airvelocity 1500, Airvelocity 1500 Firmware 2022-08-17 N/A 8.8 HIGH
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
CVE-2022-38359 1 Eyeofnetwork 1 Eyes Of Network Web 2022-08-17 N/A 8.8 HIGH
Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authenticated user to the URL https://<target-address>/module/admin_user/index.php?DataTables_Table_0_length=10&user_selected%5B%5D=1&user_mgt_list=delete_user&action=submit by means of a crafted link.
CVE-2022-2381 1 E Unlocked - Student Result Project 1 E Unlocked - Student Result 2022-08-16 N/A 8.8 HIGH
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attack
CVE-2022-35943 1 Codeigniter 2 Codeigniter, Shield 2022-08-16 N/A 8.8 HIGH
Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html) mechanism with CodeIgniter Shield. For this attack to succeed, the attacker must have direct (or indirect, e.g., XSS) control over a subdomain site (e.g., `https://a.example.com/`) of the target site (e.g., `http://example.com/`). Upgrade to **CodeIgniter v4.2.3 or later** and **Shield v1.0.0-beta.2 or later**. As a workaround: set `Config\Security::$csrfProtection` to `'session,'`remove old session data right after login (immediately after ID and password match) and regenerate CSRF token right after login (immediately after ID and password match)
CVE-2022-37043 1 Zimbra 1 Collaboration 2022-08-16 N/A 5.7 MEDIUM
An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the application that appears to be intended. The CSRF token is omitted from the request, but the request still succeeds.
CVE-2022-2355 1 Easy Username Updater Project 1 Easy Username Updater 2022-08-12 N/A 6.5 MEDIUM
The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin
CVE-2022-34158 1 Apache 1 Jspwiki 2022-08-10 N/A 8.8 HIGH
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.
CVE-2022-28731 1 Apache 1 Jspwiki 2022-08-10 N/A 6.5 MEDIUM
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
CVE-2022-34937 1 Yuba 1 U5cms 2022-08-09 N/A 8.8 HIGH
Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.
CVE-2022-36968 1 Progress 1 Ipswitch Ws Ftp Server 2022-08-09 N/A 4.3 MEDIUM
In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to mitigate the risk of cross-site request forgery (CSRF) attacks.
CVE-2022-33201 1 Mailerlite 1 Mailerlite Signup Forms 2022-08-08 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
CVE-2021-36861 1 Starfish 1 Rich Review 2022-08-07 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews.
CVE-2016-3098 1 Thoughtbot 1 Administrate 2022-08-07 N/A 5.4 MEDIUM
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
CVE-2020-35135 1 Infolific 1 Ultimate Category Excluder 2022-08-06 6.8 MEDIUM 8.8 HIGH
The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.