Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-35491 | 1 Wowza | 1 Streaming Engine | 2021-11-06 | 5.8 MEDIUM | 8.1 HIGH |
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza Streaming Engine release 4.8.14. | |||||
CVE-2020-21139 | 1 Ec Cloud E-commerce System Project | 1 Ec Cloud E-commerce System | 2021-11-05 | 4.3 MEDIUM | 6.5 MEDIUM |
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add. | |||||
CVE-2020-11060 | 1 Glpi-project | 1 Glpi | 2021-11-04 | 9.0 HIGH | 8.8 HIGH |
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, the attack is only conceivable by an account having Maintenance privileges and the right to add WIFI networks. This is fixed in version 9.4.6. | |||||
CVE-2021-29888 | 3 Ibm, Linux, Microsoft | 4 Aix, Infosphere Information Server, Linux Kernel and 1 more | 2021-11-03 | 6.8 MEDIUM | 8.8 HIGH |
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123. | |||||
CVE-2015-10001 | 1 Wp-stats Project | 1 Wp-stats | 2021-11-03 | 4.3 MEDIUM | 4.3 MEDIUM |
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads | |||||
CVE-2021-24572 | 1 Wpplugin | 1 Accept Donations With Paypal | 2021-11-03 | 4.3 MEDIUM | 4.3 MEDIUM |
The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts | |||||
CVE-2021-24799 | 1 Tipsandtricks-hq | 1 Far Future Expiry Header | 2021-11-02 | 4.3 MEDIUM | 4.3 MEDIUM |
The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |||||
CVE-2021-3901 | 1 Firefly-iii | 1 Firefly Iii | 2021-11-01 | 6.8 MEDIUM | 8.8 HIGH |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | |||||
CVE-2021-41176 | 1 Pterodactyl | 1 Panel | 2021-10-28 | 4.3 MEDIUM | 4.3 MEDIUM |
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This requires a targeted attack against a specific Panel instance, and serves only to sign a user out. **No user details are leaked, nor is any user data affected, this is simply an annoyance at worst.** This is fixed in version 1.6.3. | |||||
CVE-2021-3900 | 1 Firefly-iii | 1 Firefly Iii | 2021-10-28 | 4.3 MEDIUM | 6.5 MEDIUM |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | |||||
CVE-2019-10199 | 1 Redhat | 1 Keycloak | 2021-10-28 | 6.8 MEDIUM | 8.8 HIGH |
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain. | |||||
CVE-2021-20120 | 1 Commscope | 2 Arris Surfboard Sb8200, Arris Surfboard Sb8200 Firmware | 2021-10-27 | 6.8 MEDIUM | 8.8 HIGH |
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user. | |||||
CVE-2021-38480 | 1 Inhandnetworks | 2 Ir615, Ir615 Firmware | 2021-10-22 | 9.3 HIGH | 8.8 HIGH |
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router. | |||||
CVE-2021-24735 | 1 Tipsandtricks-hq | 1 Compact Wp Audio Player | 2021-10-22 | 4.3 MEDIUM | 6.5 MEDIUM |
The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack. | |||||
CVE-2021-39864 | 1 Adobe | 2 Commerce, Magento Open Source | 2021-10-21 | 4.3 MEDIUM | 6.5 MEDIUM |
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation. | |||||
CVE-2020-8167 | 2 Debian, Rubyonrails | 2 Debian Linux, Rails | 2021-10-21 | 4.3 MEDIUM | 6.5 MEDIUM |
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. | |||||
CVE-2021-24675 | 1 Onedesigns | 1 One User Avatar | 2021-10-20 | 4.3 MEDIUM | 6.5 MEDIUM |
The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack | |||||
CVE-2021-3858 | 1 Snipeitapp | 1 Snipe-it | 2021-10-20 | 6.8 MEDIUM | 8.8 HIGH |
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | |||||
CVE-2021-42228 | 1 Kindsoft | 1 Kindeditor | 2021-10-19 | 6.8 MEDIUM | 8.8 HIGH |
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html. | |||||
CVE-2020-19964 | 1 Phpmywind | 1 Phpmywind | 2021-10-19 | 4.3 MEDIUM | 6.5 MEDIUM |
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication. |