CWE:
 

Topic
Date
Author
Med.
Legrand BTicino Driver Manager F454 1.0.51 Cross-Site Request Forgery / Cross-Site Scripting
16.05.2019
Gjoko 'LiquidWorm' Krs...
Med.
SOCA Access Control System 180612 Cross Site Request Forgery
14.05.2019
LiquidWorm
Med.
Intelbras IWR 3000N 1.5.0 Cross Site Request Forgery
01.05.2019
Social Engineering Neo
Low
Veeam ONE Reporter 9.5.0.3201 Cross Site Request Forgery
01.05.2019
Seyed Sadegh Khatami
Low
Sierra Wireless AirLink ES450 ACEManager Cross Site Request Forgery
28.04.2019
Cisco Talos
Low
74CMS 5.0.1 Cross Site Request Forgery
24.04.2019
ax8
Low
Msvod 10 Cross Site Request Forgery
24.04.2019
ax8
Med.
WordPress Plugin Contact Form Maker 1.13.1 Cross-Site Request Forgery
14.04.2019
Panagiotis Vagenas
Low
Bolt CMS 3.6.6 Cross Site Request Forgery / Code Execution
09.04.2019
Felipe Gaspar
Low
JioFi 4G M2S 1.0.2 Cross Site Request Forgery
02.04.2019
Vikas Chaudhary
Med.
Joomla ARI Image Slider 2.2.0 CSRF Backdoor Access Vulnerability
27.03.2019
KingSkrupellos
Low
Apache CouchDB 2.3.1 Cross Site Request Forgery / Cross Site Scripting
25.03.2019
Ozer Goker
Low
Intel Modular Server System 10.18 Cross Site Request Forgery
14.03.2019
LiquidWorm
Low
PilusCart 1.4.1 Cross Site Request Forgery
13.03.2019
Gionathan Reale
Low
OrientDB 3.0.17 GA Community Edition XSS / CSRF
08.03.2019
Ozer Goker
Low
zzzphp CMS 1.6.1 Cross Site Request Forgery
05.03.2019
Yang Chenglong
Low
Simple Online Hotel Reservation System Cross Site Request Forgery
28.02.2019
Mr Winst0n
High
Kanboard 1.2.7 Code Execution / Cross Site Request Forgery
22.02.2019
Will Boucher
Low
MyBB Trash Bin 1.1.3 Cross Site Request Forgery / Cross Site Scripting
18.02.2019
0xB9
Low
LayerBB 1.1.2 Cross Site Request Forgery
15.02.2019
0xB9
Low
Jiofi 4 (JMR 1140) WiFi Password Cross Site Request Forgery
14.02.2019
Ronnie T Baby
Low
Jiofi 4 (JMR 1140) Admin Token Disclosure Cross Site Request Forgery
14.02.2019
Ronnie T Baby
Med.
Zyxel VMG3312-B10B DSL-491HNU-B1 V2 Cross Site Request Forgery
06.02.2019
Yusuf Furkan
Med.
WordPress Contact Form Email 1.2.65 CSRF / Cross Site Scripting
06.02.2019
Tim Coen
Med.
BEWARD N100 H.264 VGA IP Camera M2.1.6 Cross Site Request Forgery
04.02.2019
LiquidWorm
Med.
devolo dLAN 550 duo+ 3.1.0-1 Starter Kit Cross-Site Request Forgery
04.02.2019
Stefan Petrushevski
High
PDF Signer 3.0 Template Injection / CSRF / Code Execution
29.01.2019
dd_
Low
Zyxel NBG-418N V2 Cross Site Request Forgery
25.01.2019
Ali Can Gonullu
Low
PLC Wireless Router GPN2.4P21-C-CN Cross Site Request Forgery
23.01.2019
Kumar Saurav
Low
Hucart CMS 5.7.4 Cross Site Request Forgery
15.01.2019
AllenChen
Low
Live Call Support 1.5 Cross Site Request Forgery
15.01.2019
Ihsan Sencan
Low
Heatmiser Wifi Thermostat 1.7 Cross Site Request Forgery
10.01.2019
sajjadbnd
Med.
Ox App Suite 7.8.4 / 7.8.3 XSS / CSRF / Information Disclosure
08.01.2019
Secator
Low
Huawei E5330 21.210.09.00.158 Cross Site Request Forgery
08.01.2019
Nathu Nandwani
Med.
Webgalamb Information Disclosure / XSS / CSRF / SQL Injection
08.01.2019
Daniel Jones
Low
phpMoAdmin 1.1.5 Cross Site Request Forgery / Cross Site Scripting
08.01.2019
Ozer Goker
Low
Apache CouchDB 2.3.0 Cross Site Request Forgery
04.01.2019
Ozer Goker
Med.
WSTMart 2.0.8 Cross Site Request Forgery
25.12.2018
linfeng
Low
Hotel Booking Script 3.4 Cross Site Request Forgery
20.12.2018
Sainadh Jamalpur
Med.
Integria IMS 5.0.83 Cross Site Request Forgery
20.12.2018
Javier Olmedo
Med.
Transcend Wi-Fi SD Card Cross Site Request Forgery / Traversal
18.12.2018
MustLive
Low
PHP Server Monitor 3.3.1 Cross Site Request Forgery
04.12.2018
Javier Olmedo
Low
Synaccess netBooter NP-0801DU 7.4 Cross-Site Request Forgery (Add Admin)
28.11.2018
LiquidWorm
Low
Ticketly 1.0 Cross Site Request Forgery
20.11.2018
Javier Olmedo
Med.
Synaccess netBooter NP-0801DU 7.4 Cross Site Request Forgery
20.11.2018
LiquidWorm
Med.
Electricks eCommerce 1.0 Cross-Site Request Forgery (Change Admin Password)
14.11.2018
Nawaf Alkeraithe
High
Webiness Inventory 2.3 Cross Site Request Forgery / Shell Upload
14.11.2018
Ihsan Sencan
Low
ClipperCMS 1.3.3 Cross Site Request Forgery
14.11.2018
Ameer Pornillos
Low
Easyndexer 1.0 Cross Site Request Forgery
12.11.2018
Ihsan Sencan
Med.
OOP CMS BLOG 1.0 Cross Site Request Forgery
07.11.2018
Ihsan Sencan
Low
Card Payment 1.0 Cross Site Request Forgery
30.10.2018
Ihsan Sencan
Low
School Event Management System 1.0 Cross Site Request Forgery
30.10.2018
Ihsan Sencan
Low
School Attendance Monitoring System 1.0 Cross Site Request Forgery
30.10.2018
Ihsan Sencan
Med.
Aplaya Beach Resort Online Reservation System 1.0 CSRF / SQL Injection
30.10.2018
Ihsan Sencan
Med.
Traq 3.7.1 CSRF / XSS / SQL Injection
23.10.2018
Matt Landers
Low
PHP-SHOP Master 1.0 Cross Site Request Forgery
19.10.2018
Alireza Norkazemi
Med.
Academic Timetable Final Build 7.0b Cross Site Request Forgery
16.10.2018
Ihsan Sencan
Low
HaPe PKH 1.1 Cross Site Request Forgery
13.10.2018
Ihsan Sencan
Low
Cockpit CMS CSRF / XSS / Path Traversal
13.10.2018
Simon Uvarov
Med.
NPLUG Wireless Repeater 1.0.0.14 CSRF / XSS / Authentication Bypass
11.10.2018
Patrick Costa
Med.
matri4web v 9.04 CSRF Vulnerability
28.09.2018
indoushka
Low
Admidio 3.3.5 Cross-Site Request Forgery (Change Permissions)
04.09.2018
Nawaf Alkeraithe
Med.
phpMyAdmin 4.7.x Cross-Site Request Forgery
29.08.2018
VulnSpy
Low
Gleez CMS 1.2.0 Cross Site Request Forgery
28.08.2018
GunEggWang
Med.
RICOH MP C4504ex Printer Cross-Site Request Forgery
27.08.2018
Ismail Tasdelen
Med.
Vox TG790 ADSL Router Cross-Site Request Forgery (Add Admin)
24.08.2018
Cakes
Low
MyBB Moderator Log Notes Plugin 1.1 Cross-Site Request Forgery
20.08.2018
0xB9
Med.
Pimcore 5.2.3 SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
16.08.2018
SEC Consult
Low
TP-Link C50 Wireless Router 3 Information Disclosure Cross Site Request Forgery
10.08.2018
Wadeek
Low
TP-Link C50 Wireless Router 3 Remote Reboot Cross Site Request Forgery
10.08.2018
Wadeek
Low
onArcade 2.4.2 Cross Site Request Forgery
07.08.2018
r3m0t3nu11
Low
WityCMS 0.6.2 Cross Site Request Forgery
03.08.2018
Porhai Eung
Low
Tenda Wireless N150 Router 5.07.50 Cross Site Request Forgery
25.07.2018
Nathu Nandwani
Low
Microhard Systems 3G/4G Cellular Ethernet And Serial Gateway CSRF
17.07.2018
LiquidWorm
Low
Advanced Fertility & Genetics Centre LLC. by Nanobird Technologies CSRF Vulnerability
06.07.2018
indoushka
Low
DAMICMS 6.0.0 Cross Site Request Forgery
02.07.2018
bay0net
Low
TP-Link TL-WR841N V13 Cross Site Request Forgery
29.06.2018
Tim Coen
Low
BEESCMS 4.0 Cross Site Request Forgery
29.06.2018
bay0net
Low
NewsBee CMS 1.4 CSRF Vulnerability
28.06.2018
indoushka
Low
AsusWRT RT-AC750GF Cross Site Request Forgery
26.06.2018
Wadeek
Low
Ecessa ShieldLink SL175EHQ 10.7.4 CSRF Add Superuser Exploit
25.06.2018
LiquidWorm
Low
Ecessa WANWorx WVR-30 10.7.4 CSRF Add Superuser Exploit
25.06.2018
LiquidWorm
Med.
LFCMS 3.7.0 Cross Site Request Forgery
22.06.2018
bay0net
Med.
Joomla! Component Jomres 9.11.2 Cross-Site Request Forgery (Add User)
20.06.2018
L0RD
Med.
RabbitMQ Web Management Cross Site Request Forgery
18.06.2018
Dolev Farhi
Med.
Joomla Jomres 9.11.2 Cross Site Request Forgery
18.06.2018
Borna Nematzadeh
Low
MACCMS 10 Cross Site Request Forgery
14.06.2018
bay0net
Low
WordPress Tooltipy 5.0 Cross Site Request Forgery
13.06.2018
Tom Adams
Med.
Jenkins Mailer Cross Site Request Forgery
06.06.2018
Kl3_GMjq6
Low
GreenCMS 2.3.0603 Cross Site Request Forgery
04.06.2018
xichao
High
JDA Connect CSRF / Command Execution / Exposed JMX Service
31.05.2018
Xiaoran Wang
Low
SearchBlox 8.6.6 Cross-Site Request Forgery
30.05.2018
Ahmet Gurel
Low
Joomla! Component jCart for OpenCart 2.3.0.2 Cross-Site Request Forgery
30.05.2018
L0RD
Low
EasyService Billing 1.0 Cross-Site Request Forgery
29.05.2018
Divya Jain
Med.
Sharetronix CMS 3.6.2 Cross-Site Request Forgery / Cross-Site Scripting
28.05.2018
Hesam Bazvand
High
WordPress Peugeot Music 1.0 Shell Upload / Cross Site Request Forgery
25.05.2018
Mr.7z
Low
Timber 1.1 Cross Site Request Forgery
25.05.2018
Borna Nematzadeh
Low
Mcard Mobile Card Selling Platform 1 Cross Site Request Forgery
25.05.2018
Borna Nematzadeh
Med.
Teradek VidiU Pro 3.0.3 Change Password Cross Site Request Forgery
22.05.2018
LiquidWorm
Low
Merge PACS 7.0 Cross Site Request Forgery
22.05.2018
Safak Aslan


CVEMAP Search Results

CVE
Details
Description
2019-05-13
Medium
CVE-2019-11886

Vendor: Yellowpencil
Software: Visual css s...
 

 
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

 
Low
CVE-2018-14711

Vendor: ASUS
Software: Rt-ac3200 fi...
 

 
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.

 
Medium
CVE-2018-16136

Vendor: Ipbrick
Software: Ipbrick os
 

 
An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission of multiple forms unwillingly by a victim.

 
2019-05-10
Medium
CVE-2017-12789

Vendor: Metinfo
Software: Metinfo
 

 
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

 
Medium
CVE-2018-1790

Vendor: IBM
Software: Financial tr...
 

 
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 148944.

 
2019-05-09
Low
CVE-2017-12790

Vendor: Metinfo
Software: Metinfo
 

 
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.

 
2019-05-07
Medium
CVE-2018-13993

Updating...
 

 
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.

 
Medium
CVE-2018-2001

Vendor: IBM
Software: Curam social...
 

 
IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154891.

 
Low
CVE-2019-7746

Vendor: JIO
Software: Jmr1140 firmware
 

 
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to change the Wi-Fi password or perform a factory reset.

 
2019-05-06
Medium
CVE-2019-5430

Vendor: UI
Software: Unifi video
 

 
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.

 

 


Copyright 2019, cxsecurity.com

 

Back to Top