← Back
CWE-352

9,314 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,314)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freeswitch
1Freeswitch
Nov 21, 2024
Dec 6, 2018
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as de...Show more
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as demonstrated by an api/system?calc URI. This can also be exploited via CSRF. Alternatively, the default password of works for the freeswitch account can sometimes be used.Show less
1Kubernetes
1Minikube
Nov 21, 2024
Dec 5, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebinding to indirectly make...Show more
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebinding to indirectly make requests to the Kubernetes Dashboard, create a new Kubernetes Deployment running arbitrary code. If minikube mount is in use, the attacker could also directly access the host filesystem.Show less
1Pluck Cms
1Pluck
Nov 21, 2024
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a s...Show more
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web server user to execute a password change on the web server.Show less
1Ibm
1Storediq
Nov 21, 2024
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153118.
1Showdoc
1Showdoc
Nov 21, 2024
Nov 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
1Zyxel
1Nsa325 V2 Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms.
1Moodle
1Moodle
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6,...Show more
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.Show less
1Sikcms
1Sikcms
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.
1Bagesoft
1Bagecms
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
1Tp4a
1Teleport
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.
1Jtbc
1Jtbc Php
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.
1Jeecms
1Jeecms
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.
1Jeecms
1Jeecms
Nov 21, 2024
Nov 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.
1Greencms
1Greencms
Nov 21, 2024
Nov 20, 2018
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI.
1Control Webpanel
1Webpanel
Nov 21, 2024
Nov 20, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.
1Control Webpanel
1Webpanel
Nov 21, 2024
Nov 20, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.
1Google
1Monorail
Nov 21, 2024
Nov 20, 2018
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used t...Show more
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.Show less
1Google
1Monorail
Nov 21, 2024
Nov 20, 2018
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to ob...Show more
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.Show less
1Google
1Monorail
Nov 21, 2024
Nov 20, 2018
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obt...Show more
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.Show less