CWE-352
9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used t...Show more |
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to ob...Show more |
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obt...Show more |
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI. |
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF. |
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges. |
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account. |
1School Attendance Monitoring System Project 1School Attendance Monitoring System Nov 21, 2024 Nov 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. |
1School Attendance Monitoring System Project 1School Attendance Monitoring System Nov 21, 2024 Nov 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. |
1School Event Management System Project 1School Event Management System Nov 21, 2024 Nov 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. |
RhinOS 3.0 build 1190 allows CSRF. |
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI. |
1Tibco 1Datasynapse Gridserver Manager Nov 21, 2024 Nov 13, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery...Show more |
An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF. |
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter. |
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vu...Show more |
1Zyxel 1Zywall Usg 100 Firmware Nov 21, 2024 Nov 10, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored X...Show more |
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI. |
1Cisco 1Energy Management Suite Software Nov 21, 2024 Nov 8, 2018 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary ac...Show more |
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges. |