Vulnerabilities (CVE)

Filtered by CWE-352
Total 7225 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24763 1 Getperfectsurvey 1 Perfect Survey 2022-02-04 6.8 MEDIUM 8.8 HIGH
The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site Scripting issue which will be executed in the context of a user viewing any survey
CVE-2021-22701 1 Schneider-electric 21 Powerlogic Ion7400, Powerlogic Ion7400 Firmware, Powerlogic Ion7410 and 18 more 2022-02-03 3.5 LOW 4.5 MEDIUM
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.
CVE-2022-23888 1 Yzmcms 1 Yzmcms 2022-02-02 6.8 MEDIUM 8.8 HIGH
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
CVE-2022-23887 1 Yzmcms 1 Yzmcms 2022-02-02 4.3 MEDIUM 6.5 MEDIUM
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.
CVE-2021-44122 1 Spip 1 Spip 2022-02-02 6.8 MEDIUM 8.8 HIGH
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
CVE-2022-0269 1 Yetiforce 1 Yetiforce Customer Relationship Management 2022-01-28 6.0 MEDIUM 8.0 HIGH
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
CVE-2021-24989 1 Wpplugin 1 Accept Donations With Paypal 2022-01-28 4.3 MEDIUM 6.5 MEDIUM
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog
CVE-2021-25073 1 Webmaster-source 1 Wp125 2022-01-27 6.8 MEDIUM 8.8 HIGH
The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack
CVE-2021-24936 1 Wp Extra File Types Project 1 Wp Extra File Types 2022-01-27 6.0 MEDIUM 8.0 HIGH
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
CVE-2021-24696 1 Tipsandtricks-hq 1 Simple Download Monitor 2022-01-27 6.8 MEDIUM 8.8 HIGH
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
CVE-2022-0154 1 Gitlab 1 Gitlab 2022-01-26 6.0 MEDIUM 8.0 HIGH
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.
CVE-2021-44777 1 Email Tracker Project 1 Email Tracker 2022-01-25 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6).
CVE-2021-46028 1 Mblog Project 1 Mblog 2022-01-25 4.3 MEDIUM 4.3 MEDIUM
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
CVE-2022-0215 1 Xootix 3 Login\/signup Popup, Side Cart Woocommerce, Waitlist Woocommerce 2022-01-24 6.8 MEDIUM 8.8 HIGH
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site. This affects versions <= 2.2 in Login/Signup Popup, versions <= 2.5.1 in Waitlist Woocommerce ( Back in stock notifier ), and versions <= 2.0 in Side Cart Woocommerce (Ajax).
CVE-2022-0180 1 Expresstech 1 Quiz And Survey Master 2022-01-24 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
CVE-2022-0245 1 Livehelperchat 1 Livehelperchat 2022-01-24 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
CVE-2020-9454 1 Metagauss 1 Registrationmagic 2022-01-21 6.8 MEDIUM 8.8 HIGH
A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.
CVE-2022-0231 1 Livehelperchat 1 Live Helper Chat 2022-01-21 4.3 MEDIUM 6.5 MEDIUM
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-0226 1 Livehelperchat 1 Live Helper Chat 2022-01-21 4.3 MEDIUM 4.3 MEDIUM
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-41597 1 Salesagility 1 Suitecrm 2022-01-19 6.8 MEDIUM 8.8 HIGH
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.