Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-352
Total 4240 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-4237 1 Ibm 1 Tivoli Netcool\/impact 2020-03-31 6.8 MEDIUM 8.8 HIGH
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.
CVE-2020-4238 1 Ibm 1 Tivoli Netcool\/impact 2020-03-31 6.8 MEDIUM 8.8 HIGH
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175411.
CVE-2015-8536 1 Lenovo 1 Solution Center 2020-03-31 6.8 MEDIUM 8.8 HIGH
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow cross-site request forgery.
CVE-2020-2160 1 Jenkins 1 Jenkins 2020-03-30 6.8 MEDIUM 8.8 HIGH
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
CVE-2020-7005 1 Honeywell 1 Win-pak 2020-03-27 6.8 MEDIUM 8.8 HIGH
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.
CVE-2020-8985 1 Zend 1 Zendto 2020-03-27 6.8 MEDIUM 8.8 HIGH
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
CVE-2020-10671 1 Canon 2 Oce Colorwave 500, Oce Colorwave 500 Firmware 2020-03-23 6.8 MEDIUM 8.8 HIGH
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.
CVE-2019-12769 1 Solarwinds 1 Serv-u Managed File Transfer 2020-03-20 6.8 MEDIUM 8.8 HIGH
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
CVE-2018-21037 1 Intelliants 1 Subrion 2020-03-20 6.8 MEDIUM 8.8 HIGH
Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
CVE-2020-10568 1 Onthegosystems 1 Sitepress-multilingual-cms 2020-03-19 6.8 MEDIUM 8.8 HIGH
The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.
CVE-2020-6585 1 Nagios 1 Nagios 2020-03-19 6.8 MEDIUM 8.8 HIGH
Nagios Log Server 2.1.3 has CSRF.
CVE-2020-4199 1 Ibm 1 Tivoli Netcool\/omnibus 2020-03-19 4.3 MEDIUM 4.3 MEDIUM
IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910.
CVE-2020-10241 1 Joomla 1 Joomla\! 2020-03-18 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
CVE-2019-13199 1 Kyocera 2 Ecosys M5526cdw, Ecosys M5526cdw Firmware 2020-03-18 4.3 MEDIUM 6.5 MEDIUM
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2019-13395 1 Netgear 2 Cg3700b, Cg3700b Firmware 2020-03-18 6.8 MEDIUM 8.8 HIGH
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.
CVE-2020-10540 1 Untis 1 Webuntis 2020-03-18 6.8 MEDIUM 8.8 HIGH
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
CVE-2019-17653 1 Fortinet 1 Fortisiem 2020-03-18 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.
CVE-2019-13170 1 Xerox 2 Phaser 3320, Phaser 3320 Firmware 2020-03-17 4.3 MEDIUM 6.5 MEDIUM
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2019-10673 1 Ultimatemember 1 Ultimate Member 2020-03-16 9.3 HIGH 8.8 HIGH
A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.
CVE-2019-4726 1 Ibm 1 Sterling B2b Integrator 2020-03-12 4.3 MEDIUM 4.3 MEDIUM
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363.