Vulnerabilities (CVE)

Filtered by CWE-352
Total 7622 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25562 1 Sapphireims 1 Sapphireims 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms like account resent.
CVE-2020-25472 1 Newsscriptphp 1 News Script Php Pro 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.
CVE-2020-25453 1 Blackcat-cms 1 Blackcat Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
CVE-2020-25411 1 Online Examination System Project 1 Online Examination System 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.
CVE-2020-25408 1 College Management System Project 1 College Management System 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.
CVE-2020-25263 1 Pyrocms 1 Pyrocms 2024-11-21 5.8 MEDIUM 7.1 HIGH
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted.
CVE-2020-25262 1 Pyrocms 1 Pyrocms 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.
CVE-2020-25252 1 Hyland 1 Onbase 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Hyland OnBase through 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. CSRF can be used to log in a user, and then perform actions, because there are default credentials (the wstinol password for the manager or hsi account).
CVE-2020-25142 1 Observium 1 Observium 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable if any links and forms lack an unpredictable CSRF token. Without such a token, attackers can forge malicious requests, such as for adding Device Settings via the /addsrv URI.
CVE-2020-25095 1 Logrhythm 1 Platform Manager 2024-11-21 6.8 MEDIUM 8.8 HIGH
LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user visits a malicious site in the same browser session, that site can perform a CSRF attack to create a WebSocket from the victim client to the vulnerable PM server. Once the socket is created, the malicious site can interact with the vulnerable web server in the context of the logged-in user. This can include WebSocket payloads that result in command execution.
CVE-2020-25070 1 Usvn 1 Usvn 2024-11-21 6.8 MEDIUM 8.8 HIGH
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.
CVE-2020-25015 1 Genexis 2 Platinum 4410, Platinum 4410 Firmware 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.
CVE-2020-24984 1 Quadbase 1 Espressreports Es 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server.
CVE-2020-24983 1 Quadbase 1 Espressreports Es 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuilder within the target web application. This request will utilise the target admin session and perform the authenticated request (to change the Dashboard name) as if the victim had done so themselves, aka CSRF.
CVE-2020-24982 1 Quadbase 1 Espressdashboard 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.
CVE-2020-24922 1 Xuxueli 1 Xxl-job 2024-11-21 N/A 8.8 HIGH
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
CVE-2020-24847 1 Fruitywifi Project 1 Fruitywifi 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticated attacker can change the newSSID and hostapd_wpa_passphrase.
CVE-2020-24740 1 Pluck-cms 1 Pluck 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
CVE-2020-24739 1 Idreamsoft 1 Icms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.
CVE-2020-24570 1 Mbconnectline 2 Mbconnect24, Mymbconnect24 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.