Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-9856 | 1 Kotti Project | 1 Kotti | 2018-05-15 | 6.8 MEDIUM | 8.8 HIGH |
Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-document/@@share request. | |||||
CVE-2017-0362 | 2 Debian, Mediawiki | 2 Debian Linux, Mediawiki | 2018-05-15 | 6.8 MEDIUM | 8.8 HIGH |
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token. | |||||
CVE-2018-10127 | 1 Xyhcms Project | 1 Xyhcms | 2018-05-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the administrator role. | |||||
CVE-2018-6934 | 1 Ordermanagementscript | 1 Online Tutoring Script | 2018-05-11 | 6.8 MEDIUM | 8.8 HIGH |
CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3. | |||||
CVE-2014-5072 | 1 Wpsecurityauditlog | 1 Wp Security Audit Log | 2018-05-09 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |||||
CVE-2018-8814 | 1 Wolfcms | 1 Wolf Cms | 2018-05-09 | 5.8 MEDIUM | 6.5 MEDIUM |
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request. | |||||
CVE-2014-5034 | 1 Fresh-media | 1 Brute Force Login Protection | 2018-05-09 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that have unknown impact via a crafted request to the brute-force-login-protection page to wp-admin/options-general.php. | |||||
CVE-2018-8908 | 1 Frog Cms Project | 1 Frog Cms | 2018-05-09 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests. | |||||
CVE-2018-10048 | 1 Iscripts | 1 Eswap | 2018-05-09 | 6.8 MEDIUM | 8.8 HIGH |
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. | |||||
CVE-2018-8893 | 1 Zblogcn | 1 Z-blogphp | 2018-05-01 | 6.8 MEDIUM | 8.8 HIGH |
Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code. | |||||
CVE-2018-8972 | 1 Creditwestbank | 1 Cwcms | 2018-04-24 | 6.8 MEDIUM | 8.8 HIGH |
Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters. | |||||
CVE-2015-2009 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2018-04-23 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force ID: 103921. | |||||
CVE-2018-9134 | 1 Dedecms | 1 Dedecms | 2018-04-23 | 6.8 MEDIUM | 8.8 HIGH |
file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters. | |||||
CVE-2018-9108 | 1 Quickappscms | 1 Quickapps Cms | 2018-04-20 | 6.8 MEDIUM | 8.8 HIGH |
CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges. | |||||
CVE-2018-8764 | 2 Debian, Ldap-account-manager | 2 Debian Linux, Ldap Account Manager | 2018-04-20 | 6.8 MEDIUM | 8.8 HIGH |
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging. | |||||
CVE-2018-7700 | 1 Dedecms | 1 Dedecms | 2018-04-19 | 6.8 MEDIUM | 8.8 HIGH |
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code. | |||||
CVE-2018-1213 | 1 Dell | 1 Emc Isilon Onefs | 2018-04-19 | 6.8 MEDIUM | 8.8 HIGH |
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send unauthorized requests to the server on behalf of authenticated users of the application. | |||||
CVE-2014-2675 | 1 Wp-html-sitemap Project | 1 Wp-html-sitemap | 2018-04-18 | 5.8 MEDIUM | 6.5 MEDIUM |
Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in wp-admin/options-general.php. | |||||
CVE-2014-2274 | 1 Subscribe To Comments Reloaded Project | 1 Subscribe To Comments Reloaded | 2018-04-18 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/index.php page to wp-admin/admin.php. | |||||
CVE-2018-9923 | 1 Icmsdev | 1 Icms | 2018-04-17 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request. |