Total
8760 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-9625 | 1 Directadmin | 1 Directadmin | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
|
|||||
| CVE-2019-9604 | 1 Online Lottery Php Readymade Script Project | 1 Online Lottery Php Readymade Script | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.
|
|||||
| CVE-2019-9603 | 1 1234n | 1 Minicms | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.
|
|||||
| CVE-2019-9598 | 1 Chshcms | 1 Cscms | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
|
|||||
| CVE-2019-9597 | 1 Darktrace | 1 Enterprise Immune System | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
|
|||||
| CVE-2019-9596 | 1 Darktrace | 1 Enterprise Immune System | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
|
|||||
| CVE-2019-9549 | 1 Popojicms | 1 Popojicms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.
|
|||||
| CVE-2019-9231 | 1 Audiocodes | 8 Mediant 500-mbsr, Mediant 500-mbsr Firmware, Mediant 500l-msbr and 5 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.
|
|||||
| CVE-2019-9176 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF.
|
|||||
| CVE-2019-9062 | 1 Phpscriptsmall | 1 Online Food Ordering Script | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
|
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
|
|||||
| CVE-2019-9052 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.
|
|||||
| CVE-2019-9051 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?action=deletepage&var1= URI.
|
|||||
| CVE-2019-9049 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?action=module_delete&var1= URI.
|
|||||
| CVE-2019-9048 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /admin.php?action=theme_delete&var1= URI.
|
|||||
| CVE-2019-9040 | 1 S-cms | 1 S-cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332.
|
|||||
| CVE-2019-8991 | 1 Tibco | 5 Activematrix Bpm, Activematrix Policy Director, Activematrix Service Bus and 2 more | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid contains multiple vulnerabilities that may allow for cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. Affected releases ...
Show More |
|||||
| CVE-2019-8910 | 1 Wtcms Project | 1 Wtcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
|
|||||
| CVE-2019-8902 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 4.9 MEDIUM | 5.7 MEDIUM |
|
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
|
|||||
| CVE-2019-8447 | 1 Atlassian | 1 Jira Server | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
|
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
|
|||||
| CVE-2019-8437 | 1 Njiandan-cms Project | 1 Njiandan-cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.
|
|||||
| CVE-2019-8347 | 1 Beescms | 1 Beescms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.
|
|||||
| CVE-2019-8234 | 1 Adobe | 1 Experience Manager | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
|
|||||
| CVE-2019-8155 | 1 Magento | 1 Magento | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Magento prior to 1.9.4.3 and prior to 1.14.4.3 included a user's CSRF token in the URL of a GET request. This could be exploited by an attacker with access to network traffic to perform unauthorized actions.
|
|||||
| CVE-2019-8109 | 1 Magento | 1 Magento | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
|
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.
|
|||||
| CVE-2019-7953 | 1 Adobe | 1 Experience Manager | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
|
|||||
| CVE-2019-7947 | 1 Magento | 1 Magento | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
|
|||||
| CVE-2019-7874 | 1 Magento | 1 Magento | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of user roles.
|
|||||
| CVE-2019-7873 | 1 Magento | 1 Magento | 2024-11-21 | 5.8 MEDIUM | 4.3 MEDIUM |
|
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of the store design schedule.
|
|||||
| CVE-2019-7865 | 1 Magento | 1 Magento | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
|
|||||
| CVE-2019-7857 | 1 Magento | 1 Magento | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
|
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.
|
|||||
| CVE-2019-7851 | 1 Magento | 1 Magento | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.
|
|||||
| CVE-2019-7746 | 1 Jio | 2 Jmr1140, Jmr1140 Firmware | 2024-11-21 | 4.3 MEDIUM | 8.1 HIGH |
|
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to change the Wi-Fi password or perform a factory reset.
|
|||||
| CVE-2019-7738 | 1 C.p.sub Project | 1 C.p.sub | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
|
|||||
| CVE-2019-7737 | 1 Verydows | 1 Verydows | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.
|
|||||
| CVE-2019-7730 | 1 Mywebsql | 1 Mywebsql | 2024-11-21 | 4.9 MEDIUM | 5.7 MEDIUM |
|
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
|
|||||
| CVE-2019-7654 | 1 Wowza | 1 Streaming Engine | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza Streaming Engine 4.8.5.
|
|||||
| CVE-2019-7570 | 1 Pbootcms | 1 Pbootcms | 2024-11-21 | 5.8 MEDIUM | 6.5 MEDIUM |
|
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
|
|||||
| CVE-2019-7569 | 1 Wdoyo | 1 Doyo | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1.
|
|||||
| CVE-2019-7566 | 1 Cszcms | 1 Csz Cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
|
CSZ CMS 1.1.8 has CSRF via admin/users/new/add.
|
|||||
| CVE-2019-7440 | 1 Jio | 2 Jiofi 4g M2s, Jiofi 4g M2s Firmware | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).
|
|||||