CWE:
 

Topic
Date
Author
Med.
Transcend Wi-Fi SD Card Cross Site Request Forgery / Traversal
18.12.2018
MustLive
Low
PHP Server Monitor 3.3.1 Cross Site Request Forgery
04.12.2018
Javier Olmedo
Low
Synaccess netBooter NP-0801DU 7.4 Cross-Site Request Forgery (Add Admin)
28.11.2018
LiquidWorm
Low
Ticketly 1.0 Cross Site Request Forgery
20.11.2018
Javier Olmedo
Med.
Synaccess netBooter NP-0801DU 7.4 Cross Site Request Forgery
20.11.2018
LiquidWorm
Med.
Electricks eCommerce 1.0 Cross-Site Request Forgery (Change Admin Password)
14.11.2018
Nawaf Alkeraithe
High
Webiness Inventory 2.3 Cross Site Request Forgery / Shell Upload
14.11.2018
Ihsan Sencan
Low
ClipperCMS 1.3.3 Cross Site Request Forgery
14.11.2018
Ameer Pornillos
Low
Easyndexer 1.0 Cross Site Request Forgery
12.11.2018
Ihsan Sencan
Med.
OOP CMS BLOG 1.0 Cross Site Request Forgery
07.11.2018
Ihsan Sencan
Low
Card Payment 1.0 Cross Site Request Forgery
30.10.2018
Ihsan Sencan
Low
School Event Management System 1.0 Cross Site Request Forgery
30.10.2018
Ihsan Sencan
Low
School Attendance Monitoring System 1.0 Cross Site Request Forgery
30.10.2018
Ihsan Sencan
Med.
Aplaya Beach Resort Online Reservation System 1.0 CSRF / SQL Injection
30.10.2018
Ihsan Sencan
Med.
Traq 3.7.1 CSRF / XSS / SQL Injection
23.10.2018
Matt Landers
Low
PHP-SHOP Master 1.0 Cross Site Request Forgery
19.10.2018
Alireza Norkazemi
Med.
Academic Timetable Final Build 7.0b Cross Site Request Forgery
16.10.2018
Ihsan Sencan
Low
HaPe PKH 1.1 Cross Site Request Forgery
13.10.2018
Ihsan Sencan
Low
Cockpit CMS CSRF / XSS / Path Traversal
13.10.2018
Simon Uvarov
Med.
NPLUG Wireless Repeater 1.0.0.14 CSRF / XSS / Authentication Bypass
11.10.2018
Patrick Costa
Med.
matri4web v 9.04 CSRF Vulnerability
28.09.2018
indoushka
Low
Admidio 3.3.5 Cross-Site Request Forgery (Change Permissions)
04.09.2018
Nawaf Alkeraithe
Med.
phpMyAdmin 4.7.x Cross-Site Request Forgery
29.08.2018
VulnSpy
Low
Gleez CMS 1.2.0 Cross Site Request Forgery
28.08.2018
GunEggWang
Med.
RICOH MP C4504ex Printer Cross-Site Request Forgery
27.08.2018
Ismail Tasdelen
Med.
Vox TG790 ADSL Router Cross-Site Request Forgery (Add Admin)
24.08.2018
Cakes
Low
MyBB Moderator Log Notes Plugin 1.1 Cross-Site Request Forgery
20.08.2018
0xB9
Med.
Pimcore 5.2.3 SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
16.08.2018
SEC Consult
Low
TP-Link C50 Wireless Router 3 Information Disclosure Cross Site Request Forgery
10.08.2018
Wadeek
Low
TP-Link C50 Wireless Router 3 Remote Reboot Cross Site Request Forgery
10.08.2018
Wadeek
Low
onArcade 2.4.2 Cross Site Request Forgery
07.08.2018
r3m0t3nu11
Low
WityCMS 0.6.2 Cross Site Request Forgery
03.08.2018
Porhai Eung
Low
Tenda Wireless N150 Router 5.07.50 Cross Site Request Forgery
25.07.2018
Nathu Nandwani
Low
Microhard Systems 3G/4G Cellular Ethernet And Serial Gateway CSRF
17.07.2018
LiquidWorm
Low
Advanced Fertility & Genetics Centre LLC. by Nanobird Technologies CSRF Vulnerability
06.07.2018
indoushka
Low
DAMICMS 6.0.0 Cross Site Request Forgery
02.07.2018
bay0net
Low
TP-Link TL-WR841N V13 Cross Site Request Forgery
29.06.2018
Tim Coen
Low
BEESCMS 4.0 Cross Site Request Forgery
29.06.2018
bay0net
Low
NewsBee CMS 1.4 CSRF Vulnerability
28.06.2018
indoushka
Low
AsusWRT RT-AC750GF Cross Site Request Forgery
26.06.2018
Wadeek
Low
Ecessa ShieldLink SL175EHQ 10.7.4 CSRF Add Superuser Exploit
25.06.2018
LiquidWorm
Low
Ecessa WANWorx WVR-30 10.7.4 CSRF Add Superuser Exploit
25.06.2018
LiquidWorm
Med.
LFCMS 3.7.0 Cross Site Request Forgery
22.06.2018
bay0net
Med.
Joomla! Component Jomres 9.11.2 Cross-Site Request Forgery (Add User)
20.06.2018
L0RD
Med.
RabbitMQ Web Management Cross Site Request Forgery
18.06.2018
Dolev Farhi
Med.
Joomla Jomres 9.11.2 Cross Site Request Forgery
18.06.2018
Borna Nematzadeh
Low
MACCMS 10 Cross Site Request Forgery
14.06.2018
bay0net
Low
WordPress Tooltipy 5.0 Cross Site Request Forgery
13.06.2018
Tom Adams
Med.
Jenkins Mailer Cross Site Request Forgery
06.06.2018
Kl3_GMjq6
Low
GreenCMS 2.3.0603 Cross Site Request Forgery
04.06.2018
xichao
High
JDA Connect CSRF / Command Execution / Exposed JMX Service
31.05.2018
Xiaoran Wang
Low
SearchBlox 8.6.6 Cross-Site Request Forgery
30.05.2018
Ahmet Gurel
Low
Joomla! Component jCart for OpenCart 2.3.0.2 Cross-Site Request Forgery
30.05.2018
L0RD
Low
EasyService Billing 1.0 Cross-Site Request Forgery
29.05.2018
Divya Jain
Med.
Sharetronix CMS 3.6.2 Cross-Site Request Forgery / Cross-Site Scripting
28.05.2018
Hesam Bazvand
High
WordPress Peugeot Music 1.0 Shell Upload / Cross Site Request Forgery
25.05.2018
Mr.7z
Low
Timber 1.1 Cross Site Request Forgery
25.05.2018
Borna Nematzadeh
Low
Mcard Mobile Card Selling Platform 1 Cross Site Request Forgery
25.05.2018
Borna Nematzadeh
Med.
Teradek VidiU Pro 3.0.3 Change Password Cross Site Request Forgery
22.05.2018
LiquidWorm
Low
Merge PACS 7.0 Cross Site Request Forgery
22.05.2018
Safak Aslan
Med.
Auto Dealership And Vehicle Showroom WebSys 1.0 XSS / CSRF / SQL Injection
22.05.2018
Borna Nematzadeh
Med.
Model Agency Media House And Media Gallery 1.0 XSS / CSRF / SQL Injection
22.05.2018
Borna Nematzadeh
Low
Infinity Market Classified Ads Script 1.6.2 Cross-Site Request Forgery
21.05.2018
L0RD
Low
Healwire Online Pharmacy 3.0 Cross Site Request Forgery / Cross Site Scripting
19.05.2018
Borna Nematzadeh
Low
Siemens SIMATIC Panels Cross Site Request Forgery / Cross Site Scripting
19.05.2018
t4rkd3vilz
Low
Healwire Online Pharmacy 3.0 Persistent Cross-Site Scripting / Cross-Site Request Forgery
18.05.2018
L0RD
Med.
SuperCom Online Shopping Ecommerce Cart 1 XSS / CSRF / SQL Injection
18.05.2018
Borna Nematzadeh
Low
Powerlogic/Schneider Electric IONXXXX Series Cross Site Request Forgery
18.05.2018
t4rkd3vilz
Med.
NodAPS 4.0 SQL injection / Cross-Site Request Forgery
18.05.2018
L0RD
Low
MyBB Admin Notes 1.1 Cross Site Request Forgery
17.05.2018
0xB9
Low
Horse Market Sell And Rent Portal Script 1.5.7 CSRF
17.05.2018
L0RD
Low
Totemomail Encryption Gateway 6.0.0_Build_371 Cross Site Request Forgery
16.05.2018
Nicolas Heiniger
Low
Metronet Tag Manager 1.2.7 Cross Site Request Forgery
16.05.2018
Tom Adams
Med.
IBM Flashsystem / Storwize CSRF / Arbitrary File Read / Information Disclosure
15.05.2018
Jan Bee
Low
WordPress WP User Groups 2.0.0 Cross Site Request Forgery
12.05.2018
Tom Adams
Low
Fastweb FASTGate 0.00.47 Cross Site Request Forgery
10.05.2018
Raffaele Sabato
Low
phpVirtualBox 5.2 Cross Site Request Forgery / Cross Site Scripting
10.05.2018
Codex Lynx
Low
Easy Hosting Control Panel 0.37.12.b Cross Site Request Forgery
09.05.2018
hyp3rlinx
Low
D-Link DIR-868L 1.12 Cross Site Request Forgery
09.05.2018
Siddhartha Tripathy
Low
phpMyAdmin 4.8.0 < 4.8.0-1 Cross-Site Request Forgery
24.04.2018
revengsh
Low
WUZHI CMS 4.1.0 Cross-Site Request Forgery (Add Admin User)
11.04.2018
taoge
Med.
WolfCMS 0.8.3.1 Cross Site Request Forgery
09.04.2018
Sureshbabu Narvaneni
Med.
KYOCERA Net Admin 3.4 CSRF Add Admin Exploit
09.04.2018
Gjoko 'LiquidWorm' Krs...
Low
Cobub Razor 0.7.2 Cross Site Request Forgery
07.04.2018
ppb
Low
WampServer 3.1.2 Cross-Site Request Forgery
02.04.2018
Vipin Chaudhary
Low
WampServer 3.1.1 Cross-Site Scripting / Cross-Site Request Forgery
02.04.2018
Vipin Chaudhary
Low
Frog CMS 0.9.5 Cross-Site Request Forgery (Add User)
02.04.2018
Samrat Das
Low
MiniCMS 1.10 Cross-Site Request Forgery
31.03.2018
zixian
Low
TL-WR720N 150Mbps Wireless N Router Cross Site Request Forgery
27.03.2018
Mans van Someren
Med.
SecurEnvoy SecurMail 9.1.501 XSS / CSRF / Traversal
13.03.2018
Wolfgang Ettlinger
Med.
Magento Backups Cross Site Request Forgery
07.03.2018
DefenseCode
Low
D-Link DGS-3000-10TC Cross Site Request Forgery
01.03.2018
MustLive
Low
Bugzilla 4.4.12 / 5.0.3 Cross Site Request Forgery
19.02.2018
Holger Fuhrmannek
Low
Front Accounting ERP 2.4.3 Cross Site Request Forgery
17.02.2018
Samrat Das
Med.
Dell EMC Isilon OneFS XSS / Code Execution / CSRF
16.02.2018
CORE
Low
Tejari Cross Site Request Forgery
16.02.2018
Arvind Vishwakarma
Low
NAT32 2.2 Build 22284 Cross-Site Request Forgery
14.02.2018
hyp3rlinx
Low
TypeSetter CMS 5.1 Cross-Site Request Forgery
13.02.2018
Navina Asrani
High
Kaspersky Secure Mail Gateway 1.1.0.379 CSRF / Code Execution
07.02.2018
CORE
Low
Joomla! JS Support Ticket 1.1.0 Cross Site Request Forgery
29.01.2018
Ihsan Sencan


CVEMAP Search Results

CVE
Details
Description
2018-11-26
Medium
CVE-2018-19555

Vendor: TP4A
Software: Teleport
 

 
tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.

 
Medium
CVE-2018-19561

Vendor: Sikcms
Software: Sikcms
 

 
sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.

 
2018-11-20
Low
CVE-2018-10099

Updating...
 

 
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.

 
Low
CVE-2018-19334

Updating...
 

 
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.

 
Medium
CVE-2018-18772

Vendor: Centos-webpanel
Software: Centos web panel
 

 
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.

 
Medium
CVE-2018-18773

Vendor: Centos-webpanel
Software: Centos web panel
 

 
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

 
Medium
CVE-2018-19376

Vendor: Greencms
Software: Greencms
 

 
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI.

 
2018-11-17
Medium
CVE-2018-19327

Vendor: JTBC
Software: Jtbc php
 

 
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.

 
Medium
CVE-2018-19332

Vendor: S-cms
Software: S-cms
 

 
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.

 
2018-11-16
Low
CVE-2018-18760

Vendor: Saltos
Software: Rhinos
 

 
RhinOS 3.0 build 1190 allows CSRF.

 

 


Copyright 2018, cxsecurity.com

 

Back to Top