Total
8760 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-15695 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 6.8 MEDIUM | 6.3 MEDIUM |
|
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability.
|
|||||
| CVE-2020-15660 | 1 Mozilla | 1 Geckodriver | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
|
|||||
| CVE-2020-15600 | 1 Cmsuno Project | 1 Cmsuno | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
|
|||||
| CVE-2020-15516 | 1 Mm Forum Project | 1 Mm Forum | 2024-11-21 | 5.8 MEDIUM | 5.4 MEDIUM |
|
The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.
|
|||||
| CVE-2020-15400 | 1 Cakefoundation | 1 Cakephp | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
|
CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
|
|||||
| CVE-2020-15259 | 1 Auth0 | 1 Ad\/ldap Connector | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
|
ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or confidential data loss. CSRF exploits may occur if the user visits a malicious page containing CSRF payload on the same machine that has access to the ad-ldap-connector admin console via a browser. You may be affected if you use the admin console included with ad-ldap-connector versions <=5.0.12. If you do not have ad-ldap-connector admin console ena ...
Show More |
|||||
| CVE-2020-15182 | 2 Soy Cms Project, Soy Inquiry Project | 2 Soy Cms, Soy Inquiry | 2024-11-21 | 6.8 MEDIUM | 8.4 HIGH |
|
The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage. An administrator must be logged in for exploitation to be possible. This issue is fixed in SOY Inquiry version 2.0.0.4 and included in SOY CMS 3.0.2.328.
|
|||||
| CVE-2020-15156 | 1 Nodebb | 1 Blog Comments | 2024-11-21 | 4.3 MEDIUM | 6.8 MEDIUM |
|
In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.
|
|||||
| CVE-2020-15151 | 2 Magento, Openmage | 2 Magento, Openmage Long Term Support | 2024-11-21 | 4.0 MEDIUM | 8.0 HIGH |
|
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.
|
|||||
| CVE-2020-15135 | 1 Save-server Project | 1 Save-server | 2024-11-21 | 6.8 MEDIUM | 6.7 MEDIUM |
|
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF attack would require you to navigate to a malicious site while you have an active session with Save-Server (Session key stored in cookies). The malicious user would then be able to perform some actio ...
Show More |
|||||
| CVE-2020-15046 | 1 Supermicro | 3 X10drh-it, X10drh-it Bios, X10drh-it Firmware | 2024-11-21 | 9.3 HIGH | 8.8 HIGH |
|
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
|
|||||
| CVE-2020-15043 | 1 Iball | 2 Wrb303n, Wrb303n Firmware | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
|
|||||
| CVE-2020-15014 | 1 Pramod | 1 Blogcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
|
|||||
| CVE-2020-14989 | 1 Bloomreach | 1 Experience Manager | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows CSRF if the attacker uses GET where POST was intended.
|
|||||
| CVE-2020-14432 | 1 Netgear | 24 Rbk752, Rbk752 Firmware, Rbk753 and 21 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 before 3.2.15.25, RBS840 before 3.2.15.25, RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.
|
|||||
| CVE-2020-14369 | 1 Redhat | 1 Cloudforms | 2024-11-21 | 6.8 MEDIUM | 6.3 MEDIUM |
|
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attacker can make a forgery HTTP request to the server by crafting custom flash file which can force the user to perform state changing requests like provisioning VMs, running ansible playbooks and so forth.
|
|||||
| CVE-2020-14368 | 1 Eclipse | 1 Che | 2024-11-21 | 4.6 MEDIUM | 7.1 HIGH |
|
A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE doesn't properly set the SameSite value, allowing a Cross-Site Request Forgery (CSRF) and consequently allowing a cross-site WebSocket hijack on Theia IDE. This flaw allows an attacker to gain full access to the victim's workspace through the /services endpoint. To perform a successful attack, the attacker conducts a Man-in-the-middle attack (MITM) ...
Show More |
|||||
| CVE-2020-14319 | 1 Redhat | 2 Amq Online, Enmasse | 2024-11-21 | 4.0 MEDIUM | 5.9 MEDIUM |
|
It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks are not instigated or bypassed. For example authorised users using an older browser with Adobe Flash are vulnerable when targeted by an attacker. This flaw affects all versions of AMQ-Online prior to 1.5.2 and Enmasse versions 0.31.0-rc1 up until but not including 0.32.2.
|
|||||
| CVE-2020-14203 | 1 Ibi | 1 Webfocus Business Intelligence | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with CVE-2016-9044.
|
|||||
| CVE-2020-14043 | 1 Codiad | 1 Codiad | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in components/market/controller.php. This might cause admins to make a vulnerable request without them knowing and result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."
|
|||||
| CVE-2020-14025 | 1 Ozeki | 1 Ozeki Ng Sms Gateway | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password.
|
|||||
| CVE-2020-13868 | 1 Verbb | 1 Comments | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
|
|||||
| CVE-2020-13786 | 1 Dlink | 2 Dir-865l, Dir-865l Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
|
|||||
| CVE-2020-13760 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
|
|||||
| CVE-2020-13674 | 1 Drupal | 1 Drupal | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability.
|
|||||
| CVE-2020-13673 | 1 Drupal | 1 Entity Embed | 2024-11-21 | 2.6 LOW | 6.1 MEDIUM |
|
The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.
|
|||||
| CVE-2020-13663 | 1 Drupal | 1 Drupal | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.
|
|||||
| CVE-2020-13658 | 1 Lansweeper | 1 Lansweeper | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
|
In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.
|
|||||
| CVE-2020-13643 | 1 Siteorigin | 1 Page Builder | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.
|
|||||
| CVE-2020-13642 | 1 Siteorigin | 1 Page Builder | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.
|
|||||
| CVE-2020-13641 | 1 Infolific | 1 Real-time Find And Replace | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.
|
|||||
| CVE-2020-13620 | 1 Fastweb | 2 Fastgate Gpon Fga2130fwb, Fastgate Gpon Fga2130fwb Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.
|
|||||
| CVE-2020-13569 | 1 Open-emr | 1 Openemr | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can send an HTTP request to trigger this vulnerability.
|
|||||
| CVE-2020-13527 | 1 Lantronix | 4 Sgx, Sgx Firmware, Xport Edge and 1 more | 2024-11-21 | 3.5 LOW | 4.5 MEDIUM |
|
An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
|
|||||
| CVE-2020-13460 | 1 Tufin | 1 Securetrack | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.
|
|||||
| CVE-2020-13458 | 1 Verbb | 1 Image Resizer | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
|
|||||
| CVE-2020-13426 | 1 Bdtask | 1 Multi-scheduler | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
|
|||||
| CVE-2020-13416 | 1 Aviatrix | 1 Controller | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.
|
|||||
| CVE-2020-13412 | 1 Aviatrix | 1 Controller | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.
|
|||||
| CVE-2020-13350 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 MEDIUM | 3.1 LOW |
|
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.
|
|||||