Total
4240 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-15882 | 1 Munkireport Project | 1 Munkireport | 2020-08-05 | 5.8 MEDIUM | 8.1 HIGH |
A CSRF issue in manager/delete_machine/{id} in MunkiReport before 5.6.3 allows attackers to delete arbitrary machines from the MunkiReport database. | |||||
CVE-2020-5770 | 1 Teltonika-networks | 2 Trb245, Trb245 Firmware | 2020-08-04 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | |||||
CVE-2017-16244 | 1 Octobercms | 1 October | 2020-08-03 | 6.8 MEDIUM | 8.8 HIGH |
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable. | |||||
CVE-2020-10984 | 1 Gambio | 1 Gambio Gx | 2020-07-31 | 6.8 MEDIUM | 8.8 HIGH |
Gambio GX before 4.0.1.0 allows admin/admin.php CSRF. | |||||
CVE-2015-7715 | 1 Realtyna | 1 Realtyna Property Listing | 2020-07-30 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php. | |||||
CVE-2015-9233 | 1 Codepeople | 1 Cp Contact Form With Paypal | 2020-07-29 | 6.8 MEDIUM | 8.8 HIGH |
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. | |||||
CVE-2019-16667 | 1 Netgate | 1 Pfsense | 2020-07-27 | 6.8 MEDIUM | 8.8 HIGH |
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing. | |||||
CVE-2020-5611 | 1 Wpsocialrocket | 1 Social Sharing | 2020-07-27 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |||||
CVE-2020-5767 | 1 Icegram | 1 Email Subscribers \& Newsletters | 2020-07-21 | 4.3 MEDIUM | 6.5 MEDIUM |
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link. | |||||
CVE-2018-10232 | 1 Topdesk | 1 Topdesk | 2020-07-20 | 4.3 MEDIUM | 6.5 MEDIUM |
Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecified vectors. | |||||
CVE-2020-11438 | 1 Librehealth | 1 Librehealth Ehr | 2020-07-17 | 6.8 MEDIUM | 8.8 HIGH |
LibreHealth EMR v2.0.0 is affected by systemic CSRF. | |||||
CVE-2019-12784 | 1 Verint | 1 Impact 360 | 2020-07-16 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them to guess and potentially compromise valid credentials without ever sending any traffic from their own machine to the target site. | |||||
CVE-2020-2203 | 1 Jenkins | 1 Fortify On Demand | 2020-07-16 | 4.3 MEDIUM | 4.3 MEDIUM |
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs. | |||||
CVE-2020-15700 | 1 Joomla | 1 Joomla\! | 2020-07-15 | 6.8 MEDIUM | 6.3 MEDIUM |
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. | |||||
CVE-2020-15695 | 1 Joomla | 1 Joomla\! | 2020-07-15 | 6.8 MEDIUM | 6.3 MEDIUM |
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. | |||||
CVE-2020-10986 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2020-07-15 | 7.1 HIGH | 6.5 MEDIUM |
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page. | |||||
CVE-2020-15711 | 1 Misp | 1 Misp | 2020-07-15 | 6.8 MEDIUM | 8.8 HIGH |
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected. | |||||
CVE-2020-6289 | 1 Sap | 1 Disclosure Management | 2020-07-15 | 6.8 MEDIUM | 8.8 HIGH |
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site. | |||||
CVE-2020-15046 | 1 Supermicro | 3 X10drh-it, X10drh-it Bios, X10drh-it Firmware | 2020-07-13 | 9.3 HIGH | 8.8 HIGH |
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88. | |||||
CVE-2019-18677 | 3 Canonical, Fedoraproject, Squid-cache | 3 Ubuntu Linux, Fedora, Squid | 2020-07-10 | 5.8 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to. |