Total
7622 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-25562 | 1 Sapphireims | 1 Sapphireims | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms like account resent. | |||||
CVE-2020-25472 | 1 Newsscriptphp | 1 News Script Php Pro | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users. | |||||
CVE-2020-25453 | 1 Blackcat-cms | 1 Blackcat Cms | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. | |||||
CVE-2020-25411 | 1 Online Examination System Project | 1 Online Examination System | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user. | |||||
CVE-2020-25408 | 1 College Management System Project | 1 College Management System | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data. | |||||
CVE-2020-25263 | 1 Pyrocms | 1 Pyrocms | 2024-11-21 | 5.8 MEDIUM | 7.1 HIGH |
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted. | |||||
CVE-2020-25262 | 1 Pyrocms | 1 Pyrocms | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted. | |||||
CVE-2020-25252 | 1 Hyland | 1 Onbase | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default credentials (the wstinol password for the manager or hsi account). | |||||
CVE-2020-25142 | 1 Observium | 1 Observium | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable if any links and forms lack an unpredictable CSRF token. Without such a token, attackers can forge malicious requests, such as for adding Device Settings via the /addsrv URI. | |||||
CVE-2020-25095 | 1 Logrhythm | 1 Platform Manager | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user visits a malicious site in the same browser session, that site can perform a CSRF attack to create a WebSocket from the victim client to the vulnerable PM server. Once the socket is created, the malicious site can interact with the vulnerable web server in the context of the logged-in user. This can include WebSocket payloads that result in command execution. | |||||
CVE-2020-25070 | 1 Usvn | 1 Usvn | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature. | |||||
CVE-2020-25015 | 1 Genexis | 2 Platinum 4410, Platinum 4410 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password. | |||||
CVE-2020-24984 | 1 Quadbase | 1 Espressreports Es | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server. | |||||
CVE-2020-24983 | 1 Quadbase | 1 Espressreports Es | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuilder within the target web application. This request will utilise the target admin session and perform the authenticated request (to change the Dashboard name) as if the victim had done so themselves, aka CSRF. | |||||
CVE-2020-24982 | 1 Quadbase | 1 Espressdashboard | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account. | |||||
CVE-2020-24922 | 1 Xuxueli | 1 Xxl-job | 2024-11-21 | N/A | 8.8 HIGH |
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file. | |||||
CVE-2020-24847 | 1 Fruitywifi Project | 1 Fruitywifi | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticated attacker can change the newSSID and hostapd_wpa_passphrase. | |||||
CVE-2020-24740 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage | |||||
CVE-2020-24739 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted. | |||||
CVE-2020-24570 | 1 Mbconnectline | 2 Mbconnect24, Mymbconnect24 | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link. |