← Back
CWE-352

9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Monorail
Nov 21, 2024
Nov 20, 2018
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used t...Show more
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.Show less
1Google
1Monorail
Nov 21, 2024
Nov 20, 2018
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to ob...Show more
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.Show less
1Google
1Monorail
Nov 21, 2024
Nov 20, 2018
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obt...Show more
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.Show less
1S Cms
1S Cms
Nov 21, 2024
Nov 17, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.
1Jtbc
1Jtbc Php
Nov 21, 2024
Nov 17, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.
1Srcms Project
1Srcms
Nov 21, 2024
Nov 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
1Srcms Project
1Srcms
Nov 21, 2024
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.
1School Attendance Monitoring System Project
1School Attendance Monitoring System
Nov 21, 2024
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
1School Attendance Monitoring System Project
1School Attendance Monitoring System
Nov 21, 2024
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
1School Event Management System Project
1School Event Management System
Nov 21, 2024
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
1Saltos
1Rhinos
Jun 5, 2025
Nov 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
RhinOS 3.0 build 1190 allows CSRF.
1Dilicms
1Dilicms
Nov 21, 2024
Nov 15, 2018
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
1Tibco
1Datasynapse Gridserver Manager
Nov 21, 2024
Nov 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery...Show more
The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery (CSRF). Affected releases are TIBCO Software Inc. TIBCO DataSynapse GridServer Manager: versions up to and including 5.2.0; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; 6.2.0; 6.3.0.Show less
1Laobancms
1Laobancms
Nov 21, 2024
Nov 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF.
1Xiaocms
1Xiaocms
Nov 21, 2024
Nov 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.
1Clippercms
1Clippercms
Nov 21, 2024
Nov 11, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vu...Show more
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.Show less
1Zyxel
1Zywall Usg 100 Firmware
Nov 21, 2024
Nov 10, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored X...Show more
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.Show less
1Wstmart
1Wstmart
Nov 21, 2024
Nov 9, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.
1Cisco
1Energy Management Suite Software
Nov 21, 2024
Nov 8, 2018
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary ac...Show more
A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user.Show less
1Bagesoft
1Bagecms
Nov 21, 2024
Nov 8, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.