Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-12415 | 1 Oxid-esales | 1 Eshop | 2018-03-16 | 5.1 MEDIUM | 7.5 HIGH |
OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), and Professional Edition before 6.0.0 RC2 (development), 4.9.x before 4.9.10 (legacy) and 4.10.x before 4.10.5 (maintenance) allow remote attackers to hijack the cart session of a client via Cross-Site Request Forgery (CSRF) if the following pre-conditions are met: (1) the attacker knows which shop is presently used by the client, (2) the attacker knows the exact time when the customer will add product items to the cart, (3) the attacker knows which product items are already in the cart (has to know their article IDs), and (4) the attacker would be able to trick user into clicking a button (submit form) of an e-mail or remote site within the period of visiting the shop and placing an order. | |||||
CVE-2018-7590 | 1 Hoosk | 1 Hoosk | 2018-03-16 | 6.8 MEDIUM | 8.8 HIGH |
CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation. | |||||
CVE-2016-0295 | 1 Ibm | 1 Bigfix Platform | 2018-03-16 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363. | |||||
CVE-2018-0520 | 1 Fsi | 2 Fs010w, Fs010w Firmware | 2018-03-16 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2018-7308 | 1 Hosting Project | 1 Hosting | 2018-03-16 | 6.8 MEDIUM | 8.8 HIGH |
A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account. | |||||
CVE-2018-7216 | 1 Tejari | 1 Bravo Solution | 2018-03-16 | 6.0 MEDIUM | 8.0 HIGH |
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated users to hijack the authentication of application users for requests that modify their personal data by leveraging lack of anti-CSRF tokens. | |||||
CVE-2018-7219 | 1 5none | 1 Nonecms | 2018-03-14 | 6.8 MEDIUM | 8.8 HIGH |
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request. | |||||
CVE-2018-7176 | 1 Frontaccounting | 1 Frontaccounting | 2018-03-14 | 6.8 MEDIUM | 8.8 HIGH |
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page). | |||||
CVE-2018-6941 | 1 Nat32 | 1 Nat32 | 2018-03-13 | 6.8 MEDIUM | 8.8 HIGH |
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS. | |||||
CVE-2018-6656 | 1 Zblogcn | 1 Z-blogphp | 2018-03-13 | 5.8 MEDIUM | 6.5 MEDIUM |
Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories. | |||||
CVE-2017-17552 | 1 Zohocorp | 1 Manageengine Admanager Plus | 2018-03-13 | 6.8 MEDIUM | 8.8 HIGH |
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted. | |||||
CVE-2017-5796 | 1 Hp | 10 J9623a, J9623a Firmware, J9624a and 7 more | 2018-03-12 | 9.3 HIGH | 8.8 HIGH |
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found. | |||||
CVE-2015-2248 | 1 Sonicwall | 1 Remote Access Firmware | 2018-03-12 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark. | |||||
CVE-2017-16756 | 1 Userscape | 1 Helpspot | 2018-03-09 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account. | |||||
CVE-2016-0348 | 1 Ibm | 1 Tririga Application Platform | 2018-03-09 | 6.0 MEDIUM | 8.0 HIGH |
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111813. | |||||
CVE-2018-1000053 | 1 Limesurvey | 1 Limesurvey | 2018-03-08 | 6.8 MEDIUM | 8.8 HIGH |
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear to be exploitable via Simple HTML markup can be used to send a GET request to the affected endpoint. | |||||
CVE-2016-8513 | 1 Hp | 1 Version Control Repository Manager | 2018-03-07 | 6.0 MEDIUM | 8.0 HIGH |
A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6. | |||||
CVE-2018-6888 | 1 Typesettercms | 1 Typesetter | 2018-03-06 | 6.0 MEDIUM | 8.0 HIGH |
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token. | |||||
CVE-2017-5781 | 1 Hp | 1 Matrix Operating Environment | 2018-03-05 | 6.8 MEDIUM | 8.8 HIGH |
A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found. | |||||
CVE-2018-6288 | 1 Kaspersky | 1 Secure Mail Gateway | 2018-03-01 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1. |