VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

288 CVEsRSS

CVE-2022-30014High· 8.8
4y ago

Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.

Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.

▾ Twilightsimple_food_website_project · simple_food_websiteEPSS 0.55%via NVD
CVE-2022-25523High· 8.8
4y ago

TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.

▾ Twilighttypesettercms · typesetterEPSS 0.55%via NVD
CVE-2022-23349High· 8.8
4y ago

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

▾ Twilightbigantsoft · bigant_serverEPSS 0.65%via NVD
CVE-2020-18326High· 8.8PoC
4y ago

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfull…

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfull…

▾ Midnightintelliants · subrion_cmsEPSS 2.2%via NVD
CVE-2021-44227High· 8.0
4y ago

mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)

A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 8.2)EPSS 0.76%via CSAF
CVE-2020-19964Medium· 6.5
4y ago

A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.

A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.

▾ Sunlitphpmywind · phpmywindEPSS 0.52%via NVD
CVE-2020-20586Medium· 4.5
5y ago

A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password.

A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password.

▾ Sunlitxyhcms · xyhcmsEPSS 0.39%via NVD
CVE-2021-31659High· 8.8
5y ago

TP-Link TL-SG2005, TL-SG2008, etc

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A maliciou…

▾ Twilighttp-link · tl-sg2005_firmwareEPSS 0.56%via NVD
CVE-2020-21884High· 8.8
5y ago

Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which …

Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which …

▾ Twilightindionetworks · unibox_u50_firmwareEPSS 1.2%via NVD
CVE-2021-26215Medium· 4.3
5y ago

SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.

SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.

▾ Sunlitseeddms · seeddmsEPSS 0.49%via NVD
CVE-2021-26216Medium· 4.3
5y ago

SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.

SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.

▾ Sunlitseeddms · seeddmsEPSS 0.49%via NVD
CVE-2020-27574High· 8.8
5y ago

Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF)

Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web application as the authenticated user.

▾ Twilightmaxum · rumpusEPSS 0.76%via NVD
CVE-2020-35273High· 8.0
5y ago

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.

▾ Twilightegavilanmedia · user_registration_&_login_system_with_admin_panelEPSS 0.57%via NVD
CVE-2020-28858High· 8.8
5y ago

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

▾ Twilightopenasset · digital_asset_managementEPSS 1.1%via NVD
CVE-2020-23451High· 8.8
6y ago

Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

▾ Twilightspiceworks · spiceworksEPSS 0.59%via NVD
CVE-2020-15711High· 8.8
6y ago

In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.

In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.

▾ Twilightmisp-project · mispEPSS 0.49%via NVD
CVE-2020-1103Medium· 6.5
6y ago

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultan…

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultan…

▾ Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 2.4%via NVD
CVE-2019-13529High· 8.8PoC
6y ago

An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior

An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses …

▾ Midnightsma · sunny_webbox_firmwareEPSS 3.1%via NVD
CWE-352 vulnerabilities (CVEs) — page 10 · VulnSea