Vulnerabilities (CVE)

Filtered by CWE-352
Angry Yack Logo
Total 8760 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-6007 1 Joomsky 1 Js Support Ticket 2024-11-21 6.8 MEDIUM 8.8 HIGH
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.
CVE-2018-5976 1 Rsvp Invitation Online Project 1 Rsvp Invitation Online 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password.
CVE-2018-5969 1 Photography Cms Project 1 Photography Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin account.
CVE-2018-5921 1 Hp 387 A2w75a, A2w75a Firmware, A2w76a and 384 more 2024-11-21 6.8 MEDIUM 8.8 HIGH
A potential security vulnerability has been identified with certain HP printers and MFPs in 2405129_000052 and other firmware versions. This vulnerability is known as Cross Site Request Forgery, and could potentially be exploited remotely to allow elevation of privilege.
CVE-2018-5720 1 Dodocool 2 Dc38, Dc38 Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify all the settings. This vulnerability can lead to changing an existing user's username and password, changing the Wi-Fi password, etc.
CVE-2018-5673 1 Booking Calendar Project 1 Booking Calendar 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.
CVE-2018-5669 1 Read And Understood Project 1 Read And Understood 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php.
CVE-2018-5658 1 Responsive Coming Soon Page Project 1 Responsive Coming Soon Page 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.
CVE-2018-5656 1 Weblizar 1 Pinterest-feeds 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.
CVE-2018-5368 1 Srbtranslatin Project 1 Srbtranslatin 2024-11-21 6.8 MEDIUM 8.8 HIGH
The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.
CVE-2018-5361 1 Wpglobus 1 Wpglobus 2024-11-21 6.8 MEDIUM 8.8 HIGH
The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.
CVE-2018-5329 1 Beims 1 Contractorweb.net 2024-11-21 6.8 MEDIUM 8.8 HIGH
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.
CVE-2018-5301 1 Magento 1 Magento 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.
CVE-2018-5285 1 Wpscoop 1 Imageinject 2024-11-21 6.8 MEDIUM 8.8 HIGH
The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php.
CVE-2018-5123 1 Mozilla 1 Bugzilla 2024-11-21 6.8 MEDIUM 8.8 HIGH
A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4.
CVE-2018-5073 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2024-11-21 6.0 MEDIUM 6.8 MEDIUM
Online Ticket Booking has CSRF via admin/movieedit.php.
CVE-2018-4066 1 Sierrawireless 2 Airlink Es450, Airlink Es450 Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an authenticated user. An attacker can get an authenticated user to request authenticated pages on the attacker's behalf to trigger this vulnerability.
CVE-2018-2474 1 Sap 1 Fiori 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.
CVE-2018-2442 1 Sap 2 Businessobjects Business Intelligence, Internet Graphics Server 2024-11-21 6.8 MEDIUM 8.8 HIGH
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
CVE-2018-2001 1 Ibm 1 Curam Social Program Management 2024-11-21 6.8 MEDIUM 4.3 MEDIUM
IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154891.
CVE-2018-2000 1 Ibm 2 Business Automation Workflow, Business Process Manager 2024-11-21 6.8 MEDIUM 4.3 MEDIUM
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154890.
CVE-2018-25096 1 Petrk94 1 Ownhealthrecord 2024-11-21 5.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in MdAlAmin-aol Own Health Record 0.1-alpha/0.2-alpha/0.3-alpha/0.3.1-alpha. It has been rated as problematic. This issue affects some unknown processing of the file includes/logout.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Upgrading to version 0.4-alpha is able to address this issue. The patch is named 58b413aa40820b49070782c786c526850ab7748f. It is recommended to upgrade the affected component. The associated iden ...

Show More

CVE-2018-21160 1 Netgear 1 Readynas Os 2024-11-21 6.8 MEDIUM 8.8 HIGH
NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.
CVE-2018-21120 1 Netgear 22 Wac120, Wac120 Firmware, Wac505 and 19 more 2024-11-21 6.0 MEDIUM 8.0 HIGH
Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7, WND930 before 2.1.5, and WN604 before 3.3.10.
CVE-2018-21102 1 Netgear 1 Readynas Os Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.
CVE-2018-21096 1 Netgear 22 Wac120, Wac120 Firmware, Wac505 and 19 more 2024-11-21 4.9 MEDIUM 7.4 HIGH
Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7, WND930 before 2.1.5, and WN604 before 3.3.10.
CVE-2018-21037 1 Intelliants 1 Subrion 2024-11-21 6.8 MEDIUM 8.8 HIGH
Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
CVE-2018-21006 1 Bbpress Move Topics Project 1 Bbpress Move Topics 2024-11-21 6.8 MEDIUM 8.8 HIGH
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
CVE-2018-21002 1 Joomsky 1 Js Help Desk 2024-11-21 6.8 MEDIUM 8.8 HIGH
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
CVE-2018-20974 1 Joomsky 1 Js Job Manager 2024-11-21 6.8 MEDIUM 8.8 HIGH
The js-jobs plugin before 1.0.7 for WordPress has CSRF.
CVE-2018-20972 1 Codeermeneer 1 Companion Auto Update 2024-11-21 6.8 MEDIUM 8.8 HIGH
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
CVE-2018-20971 1 Churchadminplugin 1 Church Admin 2024-11-21 6.8 MEDIUM 8.8 HIGH
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
CVE-2018-20968 1 Smackcoders 1 Ultimate Exporter 2024-11-21 6.8 MEDIUM 8.8 HIGH
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
CVE-2018-20967 1 Smackcoders 1 Import All Pages\, Post Types\, Products\, Orders\, And Users As Xml \& Csv 2024-11-21 6.8 MEDIUM 8.8 HIGH
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
CVE-2018-20964 1 Codepeople 1 Contact Form Email 2024-11-21 6.8 MEDIUM 8.8 HIGH
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
CVE-2018-20872 1 I-lan 1 Draytekl Firmware 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.
CVE-2018-20848 1 Peel 1 Peel Shopping 2024-11-21 6.8 MEDIUM 8.8 HIGH
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.
CVE-2018-20816 1 Salesagility 1 Suitecrm 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
CVE-2018-20780 1 Traq 1 Traq 2024-11-21 6.8 MEDIUM 8.8 HIGH
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
CVE-2018-20728 1 Nedi 1 Nedi 2024-11-21 6.8 MEDIUM 8.8 HIGH
A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.