Vulnerabilities (CVE)

Filtered by CWE-352
Total 5731 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14959 1 Weaselcms Project 1 Weaselcms 2018-10-04 6.8 MEDIUM 8.8 HIGH
An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI.
CVE-2018-14978 1 Q-cms 1 Qcms 2018-10-03 6.8 MEDIUM 8.8 HIGH
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
CVE-2018-14910 1 Seacms 1 Seacms 2018-10-02 6.8 MEDIUM 8.8 HIGH
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be exploited through CSRF.
CVE-2018-14926 1 Matera 1 Banco 2018-10-02 6.8 MEDIUM 8.8 HIGH
Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.
CVE-2018-14908 1 Samsung 1 Syncthru Web Service 2018-09-27 6.8 MEDIUM 8.8 HIGH
Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action.
CVE-2018-14603 1 Gitlab 1 Gitlab 2018-09-18 6.8 MEDIUM 8.8 HIGH
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in the Test feature of the System Hooks component.
CVE-2018-14582 1 Bagesoft 1 Bagecms 2018-09-18 6.8 MEDIUM 8.8 HIGH
index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.
CVE-2018-14583 1 Xyhcms 1 Xyhcms 2018-09-18 6.8 MEDIUM 8.8 HIGH
xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account.
CVE-2018-14331 1 Xiaocms 1 Xiaocms X1 2018-09-17 6.8 MEDIUM 8.8 HIGH
An issue was discovered in XiaoCms X1 v20140305. There is a CSRF vulnerability to change the administrator account password via admin/index.php?c=index&a=my.
CVE-2018-14421 1 Seacms 1 Seacms 2018-09-14 6.8 MEDIUM 8.8 HIGH
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
CVE-2018-14420 1 Metinfo 1 Metinfo 2018-09-14 6.8 MEDIUM 8.8 HIGH
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
CVE-2018-14069 1 Srcms Project 1 Srcms 2018-09-10 6.0 MEDIUM 8.8 HIGH
An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add.
CVE-2018-14068 1 Srcms Project 1 Srcms 2018-09-10 6.8 MEDIUM 8.8 HIGH
An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add.
CVE-2018-13793 1 Abbyy 1 Flexicapture 2018-09-07 6.8 MEDIUM 8.8 HIGH
Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Verification, Web Scanning, Web Capture, Monitoring and Administration, and Login.
CVE-2018-14029 1 Creatiwity 1 Witycms 2018-09-06 6.8 MEDIUM 8.8 HIGH
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field.
CVE-2018-13989 1 Arcelikas 2 Grundig Smart Inter\@ctive, Grundig Smart Inter\@ctive Firmware 2018-09-06 8.3 HIGH 8.8 HIGH
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device.
CVE-2018-14014 1 Super Cms Project 1 Super Cms 2018-09-06 6.8 MEDIUM 8.8 HIGH
In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=adminadd.
CVE-2018-11349 1 Jirafeau 1 Jirafeau 2018-09-05 6.8 MEDIUM 8.8 HIGH
The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and search_link.
CVE-2018-12529 1 Intex 2 N150, N150 Firmware 2018-09-05 6.8 MEDIUM 8.8 HIGH
An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.
CVE-2018-12574 1 Tp-link 2 Tl-wr841n, Tl-wr841n Firmware 2018-09-04 6.8 MEDIUM 8.8 HIGH
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.