Vulnerabilities (CVE)

Filtered by CWE-352
Total 5731 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-13067 1 Opencart 1 Opencart 2018-09-04 6.8 MEDIUM 8.8 HIGH
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's password.
CVE-2018-11636 1 Dialogic 1 Powermedia Xms 2018-08-31 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execute malicious and unauthorized actions.
CVE-2018-13032 1 Ecessa 2 Shieldlink Sl175ehq, Shieldlink Sl175ehq Firmware 2018-08-31 6.8 MEDIUM 8.8 HIGH
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.
CVE-2018-1000506 1 Mediaron 1 Metronet Tag Manager 2018-08-30 6.8 MEDIUM 8.8 HIGH
Metronet Tag Manager version 1.2.7 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page /wp-admin/options-general.php?page=metronet-tag-manager that can result in allows anybody to do almost anything an admin can. This attack appear to be exploitable via Logged in user must follow a link. This vulnerability appears to have been fixed in 1.2.9.
CVE-2018-1000507 1 Jjj 1 Wp User Groups 2018-08-30 4.3 MEDIUM 6.5 MEDIUM
WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1.
CVE-2018-1000505 1 Tooltipy 1 Tooltipy 2018-08-30 4.3 MEDIUM 6.5 MEDIUM
Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts. This attack appear to be exploitable via Admin must follow a link. This vulnerability appears to have been fixed in 5.1.
CVE-2018-13445 1 Seacms 1 Seacms 2018-08-28 6.8 MEDIUM 8.8 HIGH
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?action=add.
CVE-2018-13444 1 Seacms 1 Seacms 2018-08-28 6.8 MEDIUM 8.8 HIGH
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2.
CVE-2018-13340 1 Gleeztech 1 Gleez Cms 2018-08-28 6.8 MEDIUM 8.8 HIGH
Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
CVE-2018-12602 1 Lfdycms 1 Lfcms 2018-08-27 6.8 MEDIUM 8.8 HIGH
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
CVE-2018-12603 1 Lfdycms 1 Lfcms 2018-08-27 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.
CVE-2018-12739 1 Beescms 1 Beescms 2018-08-27 6.8 MEDIUM 8.8 HIGH
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
CVE-2018-13010 1 Wstmall 1 Wstmall 2018-08-24 6.8 MEDIUM 8.8 HIGH
WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account.
CVE-2018-13407 1 Jirafeau 1 Jirafeau 2018-08-23 5.5 MEDIUM 4.9 MEDIUM
A CSRF issue was discovered in Jirafeau before 3.4.1. The "delete file" feature on the admin panel is not protected against automated requests and could be abused.
CVE-2018-1000514 1 Limesurvey 1 Limesurvey 2018-08-20 4.3 MEDIUM 4.3 MEDIUM
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result in CSRF admins to delete boxes. This vulnerability appears to have been fixed in 3.6.x.
CVE-2018-12971 1 Easycms 1 Easycms 2018-08-20 5.8 MEDIUM 6.5 MEDIUM
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
CVE-2018-12582 1 Akcms Project 1 Akcms 2018-08-09 6.8 MEDIUM 8.8 HIGH
An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI.
CVE-2018-12583 1 Akcms Project 1 Akcms 2018-08-09 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.
CVE-2018-12659 1 Slims Akasia Project 1 Slims Akasia 2018-08-08 6.8 MEDIUM 8.8 HIGH
SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.
CVE-2017-5394 2 Google, Mozilla 2 Android, Firefox 2018-08-07 6.8 MEDIUM 8.8 HIGH
A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.