Total
8760 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-9266 | 1 Soplanning | 1 Soplanning | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
|
|||||
| CVE-2020-9042 | 1 Couchbase | 1 Couchbase Server | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request.
|
|||||
| CVE-2020-9018 | 1 Litecart | 1 Litecart | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
|
|||||
| CVE-2020-8985 | 1 Zend | 1 Zendto | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
|
|||||
| CVE-2020-8976 | 1 Zigor | 2 Zgr Tps200 Ng, Zgr Tps200 Ng Firmware | 2024-11-21 | N/A | 9.6 CRITICAL |
|
The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious request.
|
|||||
| CVE-2020-8830 | 1 Commscope | 2 Ruckus Zoneflex R500, Ruckus Zoneflex R500 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
|
|||||
| CVE-2020-8829 | 1 Intelbras | 2 Cip 92200, Cip 92200 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.
|
|||||
| CVE-2020-8658 | 1 Bestwebsoft | 1 Htaccess | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.
|
|||||
| CVE-2020-8615 | 1 Themeum | 1 Tutor Lms | 2024-11-21 | 2.6 LOW | 6.5 MEDIUM |
|
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
|
|||||
| CVE-2020-8505 | 1 Arox | 1 School Management Software Php\/mysql | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
|
|||||
| CVE-2020-8504 | 1 Arox | 1 School Management Software Php\/mysql | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.
|
|||||
| CVE-2020-8465 | 1 Trendmicro | 1 Interscan Web Security Virtual Appliance | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.
|
|||||
| CVE-2020-8461 | 1 Trendmicro | 1 Interscan Web Security Virtual Appliance | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.
|
|||||
| CVE-2020-8425 | 1 Cups Easy \(purchase \& Inventory\) Project | 1 Cups Easy \(purchase \& Inventory\) | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
|
|||||
| CVE-2020-8424 | 1 Cups Easy Project | 1 Cups Easy | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
|
|||||
| CVE-2020-8420 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
|
|||||
| CVE-2020-8419 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
|
|||||
| CVE-2020-8417 | 1 Codesnippets | 1 Code Snippets | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
|
|||||
| CVE-2020-8282 | 1 Ui | 4 Edgemax Edgepower 24v, Edgemax Edgepower 24v Firmware, Edgemax Edgepower 54v and 1 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.
|
|||||
| CVE-2020-8168 | 1 Ui | 51 Ag-hp-2g16, Ag-hp-2g20, Ag-hp-5g23 and 48 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against cross-site request forgery (CSRF), as a result authenticated users can be persuaded to visit malicious web pages, which allows attackers to perform arbitrary actions, such as downgrade the device's firmware to older vers ...
Show More |
|||||
| CVE-2020-8167 | 2 Debian, Rubyonrails | 2 Debian Linux, Rails | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
|
|||||
| CVE-2020-8166 | 2 Debian, Rubyonrails | 2 Debian Linux, Rails | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
|
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
|
|||||
| CVE-2020-7991 | 1 Adive | 1 Framework | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
|
|||||
| CVE-2020-7988 | 1 Phpipam | 1 Phpipam | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.
|
|||||
| CVE-2020-7983 | 1 Commscope | 2 Ruckus Zoneflex R500, Ruckus Zoneflex R500 Firmware | 2024-11-21 | 5.8 MEDIUM | 8.1 HIGH |
|
A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks.
|
|||||
| CVE-2020-7965 | 1 Webargs Project | 1 Webargs | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.
|
|||||
| CVE-2020-7780 | 1 Softwaremill | 1 Akka-http-session | 2024-11-21 | 6.8 MEDIUM | 6.3 MEDIUM |
|
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.
|
|||||
| CVE-2020-7534 | 1 Schneider-electric | 20 140cpu65, 140cpu65 Firmware, 140noc78000 and 17 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) ( ...
Show More |
|||||
| CVE-2020-7503 | 1 Schneider-electric | 2 Easergy T300, Easergy T300 Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.
|
|||||
| CVE-2020-7336 | 1 Mcafee | 1 Network Security Management | 2024-11-21 | 4.3 MEDIUM | 6.6 MEDIUM |
|
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
|
|||||
| CVE-2020-7332 | 1 Mcafee | 1 Endpoint Security | 2024-11-21 | 6.8 MEDIUM | 7.0 HIGH |
|
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.
|
|||||
| CVE-2020-7304 | 1 Mcafee | 1 Data Loss Prevention | 2024-11-21 | 5.2 MEDIUM | 7.6 HIGH |
|
Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.
|
|||||
| CVE-2020-7210 | 1 Umbraco | 1 Umbraco Cms | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
|
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
|
|||||
| CVE-2020-7201 | 1 Hp | 4 Storeever 1\/8 G2 Tape Autoloader, Storeever 1\/8 G2 Tape Autoloader Firmware, Storeever Msl2024 and 1 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).
|
|||||
| CVE-2020-7029 | 1 Avaya | 2 Aura Communication Manager, Aura Messaging | 2024-11-21 | 6.8 MEDIUM | 6.4 MEDIUM |
|
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.
|
|||||
| CVE-2020-7005 | 1 Honeywell | 1 Win-pak | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.
|
|||||
| CVE-2020-6849 | 1 Hutchhouse | 1 Marketo Forms And Tracking | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
|
|||||
| CVE-2020-6844 | 1 Topmanage | 1 Olk Webstore | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.
|
|||||
| CVE-2020-6776 | 1 Bosch | 4 Praesensa, Praesensa Firmware, Praesideo and 1 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (Cross-Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or submitting a malicious form. A successful exploit allows the attacker to perform arbitrary actions with the privileges of the vic ...
Show More |
|||||
| CVE-2020-6585 | 1 Nagios | 1 Nagios | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Nagios Log Server 2.1.3 has CSRF.
|
|||||