Vulnerabilities (CVE)

Filtered by CWE-352
Total 7225 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-7822 1 Buffalotech 2 Wnc01wh, Wnc01wh Firmware 2017-06-15 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers to hijack the authentication of a logged in user to perform unintended operations via unspecified vectors.
CVE-2015-1786 1 Zend 1 Zend Framework 2017-06-15 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.
CVE-2016-9991 1 Ibm 1 Sterling Selling And Fulfillment Foundation 2017-06-14 6.0 MEDIUM 8.0 HIGH
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.
CVE-2017-9517 1 Atmail 1 Atmail 2017-06-13 6.8 MEDIUM 8.8 HIGH
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
CVE-2017-9518 1 Atmail 1 Atmail 2017-06-13 6.8 MEDIUM 8.8 HIGH
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
CVE-2017-9519 1 Atmail 1 Atmail 2017-06-13 6.8 MEDIUM 8.8 HIGH
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
CVE-2016-4909 1 Cybozu 1 Garoon 2017-06-13 4.3 MEDIUM 4.3 MEDIUM
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.
CVE-2016-4907 1 Cybozu 1 Garoon 2017-06-13 6.8 MEDIUM 8.8 HIGH
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.
CVE-2017-9444 1 Bigtreecms 1 Bigtree Cms 2017-06-12 6.8 MEDIUM 8.8 HIGH
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI.
CVE-2016-8229 1 Lenovo 1 Lenovo Service Bridge 2017-06-09 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.
CVE-2016-8941 1 Ibm 2 Spectrum Control, Tivoli Storage Productivity Center 2017-06-08 6.8 MEDIUM 8.8 HIGH
IBM Tivoli Storage Productivity Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVE-2017-9365 1 Bigtreecms 1 Bigtree Cms 2017-06-06 6.8 MEDIUM 8.8 HIGH
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.
CVE-2017-9379 1 Bigtreecms 1 Bigtree Cms 2017-06-06 6.8 MEDIUM 8.8 HIGH
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to core\admin\modules\dashboard\vitals-statistics\404\create-301.php.
CVE-2017-8382 1 Admidio 1 Admidio 2017-06-05 3.5 LOW 4.5 MEDIUM
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.
CVE-2016-4854 1 Nttdocomo 2 L-04d, L-04d Firmware 2017-05-31 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of administrators to perform arbitrary operations via unspecified vectors.
CVE-2016-4904 1 Wp-olivecart 2 Olivecart, Olivecartpro 2017-05-30 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to hijack the authentication of a user to perform unintended operations via unspecified vectors.
CVE-2017-8930 1 Simpleinvoices 1 Simple Invoices 2017-05-25 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application, (2) create regular user accounts, or (3) change configuration parameters such as tax rates and the enable/disable status of PayPal payment modules.
CVE-2016-7980 1 Spip 1 Spip 2017-05-24 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.
CVE-2017-7491 1 Moodle 1 Moodle 2017-05-23 4.3 MEDIUM 4.3 MEDIUM
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
CVE-2016-4891 1 Setucocms Project 1 Setucocms 2017-05-23 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors.