Vulnerabilities (CVE)

Filtered by CWE-352
Total 7225 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24801 1 Wp Survey Plus Project 1 Wp Survey Plus 2022-07-30 4.3 MEDIUM 4.3 MEDIUM
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issues
CVE-2021-31584 1 Sipwise 1 Next Generation Communication Platform 2022-07-30 6.8 MEDIUM 8.8 HIGH
Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges.
CVE-2019-5963 1 Zoho 1 Salesiq 2022-07-29 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2022-2071 1 Name Directory Project 1 Name Directory 2022-07-29 N/A 6.1 MEDIUM
The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.
CVE-2022-35285 2 Ibm, Linux 2 Security Verify Information Queue, Linux Kernel 2022-07-29 N/A 8.8 HIGH
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812.
CVE-2021-24565 1 Contact Form 7 Captcha Project 1 Contact Form 7 Captcha 2022-07-28 6.8 MEDIUM 8.8 HIGH
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
CVE-2022-34367 1 Dell 1 Emc Data Protection Central 2022-07-27 N/A 8.8 HIGH
Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, leading to processing of unintended server operations.
CVE-2022-22359 1 Ibm 2 Partner Engagement Manager, Partner Engagement Manager On Cloud\/saas 2022-07-27 N/A 6.5 MEDIUM
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.
CVE-2022-29495 1 Sygnoos 1 Popup Builder 2022-07-26 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
CVE-2022-29454 1 Wordplus 1 Better Messages 2022-07-26 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.
CVE-2022-32320 2 Ferdium, Getferdi 2 Ferdium, Ferdi 2022-07-25 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file.
CVE-2020-5397 2 Oracle, Vmware 27 Application Testing Suite, Communications Brm - Elastic Charging Engine, Communications Diameter Signaling Router and 24 more 2022-07-25 2.6 LOW 5.3 MEDIUM
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.
CVE-2021-38868 1 Ibm 1 Engineering Requirements Quality Assistant On-premises 2022-07-25 N/A 6.5 MEDIUM
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.
CVE-2022-32289 1 Sygnoos 1 Popup Builder 2022-07-25 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.
CVE-2022-30337 1 Joomunited 1 Wp Meta Seo 2022-07-25 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 4.4.8 at WordPress allows an attacker to update the social settings.
CVE-2022-1672 1 Insights From Google Pagespeed Project 1 Insights From Google Pagespeed 2022-07-18 6.8 MEDIUM 8.8 HIGH
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
CVE-2022-2091 1 Cache Images Project 1 Cache Images 2022-07-18 4.3 MEDIUM 6.5 MEDIUM
The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.
CVE-2022-2144 1 Jquery Validation For Contact Form 7 Project 1 Jquery Validation For Contact Form 7 2022-07-18 4.3 MEDIUM 4.3 MEDIUM
The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack
CVE-2020-35773 1 Freehtmldesigns 1 Site Offline 2022-07-17 6.8 MEDIUM 8.8 HIGH
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
CVE-2022-2123 1 Wp Opt-in Project 1 Wp Opt-in 2022-07-15 4.3 MEDIUM 4.3 MEDIUM
The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.