Total
7857 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-15846 | 1 Fledrcms Project | 1 Fledrcms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=done&savedata=1. | |||||
CVE-2018-15845 | 1 Gleezcms | 1 Gleez Cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add. | |||||
CVE-2018-15844 | 1 Damicms | 1 Damicms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit. | |||||
CVE-2018-15702 | 1 Tp-link | 2 Tl-wrn841n, Tl-wrn841n Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field. | |||||
CVE-2018-15682 | 1 Btiteam | 1 Xbtit | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending private messages to users by luring an authenticated user to a web page that automatically submits a form on their behalf. | |||||
CVE-2018-15677 | 1 Btiteam | 1 Xbtit | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF. | |||||
CVE-2018-15612 | 1 Avaya | 1 Orchestration Designer | 2024-11-21 | 6.8 MEDIUM | 8.3 HIGH |
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1. | |||||
CVE-2018-15569 | 1 Mylittleforum | 1 My Little Forum | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
my little forum 2.4.12 allows CSRF for deletion of users. | |||||
CVE-2018-15568 | 1 Tp5cms Project | 1 Tp5cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html. | |||||
CVE-2018-15565 | 1 Simple-cms Project | 1 Simple Cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can also be exploited via CSRF. | |||||
CVE-2018-15564 | 1 Simple-cms Project | 1 Simple Cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8. | |||||
CVE-2018-15539 | 1 Agentejo | 1 Cockpit | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc. | |||||
CVE-2018-15445 | 1 Cisco | 1 Energy Management Suite Software | 2024-11-21 | 6.0 MEDIUM | 6.3 MEDIUM |
A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. | |||||
CVE-2018-15438 | 1 Cisco | 1 Prime Collaboration Assurance | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to use a web browser to perform arbitrary actions with the privileges of the user on an affected system. | |||||
CVE-2018-15402 | 1 Cisco | 1 Enterprise Network Virtualization Software | 2024-11-21 | 6.8 MEDIUM | 5.4 MEDIUM |
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks. The vulnerability is due to improper validation of Origin headers on HTTP requests within the management interface. An attacker could exploit this vulnerability by convincing a targeted user to follow a URL to a malicious website. An exploit could allow the attacker to take actions within the software with the privileges of the targeted user or gain access to sensitive information. | |||||
CVE-2018-15401 | 1 Cisco | 1 Hosted Collaboration Mediation Fulfillment | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system via a web browser and with the privileges of the user. | |||||
CVE-2018-15334 | 1 F5 | 1 Big-ip Access Policy Manager | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication. | |||||
CVE-2018-15206 | 1 Bpcbt | 1 Smartvista | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf. | |||||
CVE-2018-15203 | 1 Ignitedcms | 1 Ignitedcms | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages. | |||||
CVE-2018-15202 | 1 Juunan06 | 1 Ecommerce | 2024-11-21 | 6.8 MEDIUM | 6.3 MEDIUM |
An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.php that can add new users and add products. |