Vulnerabilities (CVE)

Filtered by CWE-352
Total 7538 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16966 1 Filemanagerpro 1 File Manager 2024-11-21 6.8 MEDIUM 8.8 HIGH
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
CVE-2018-16952 1 Oracle 1 Webcenter Interaction 2024-11-21 6.8 MEDIUM 8.8 HIGH
The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its design. The impact is sensitive actions in the portal (such as changing a portal user's password). NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.
CVE-2018-16951 1 Xunfeng Project 1 Xunfeng 2024-11-21 6.0 MEDIUM 8.0 HIGH
xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832.
CVE-2018-16854 1 Moodle 1 Moodle 2024-11-21 6.8 MEDIUM 6.5 MEDIUM
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.
CVE-2018-16832 1 Xunfeng Project 1 Xunfeng 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.
CVE-2018-16795 1 Open-emr 1 Openemr 2024-11-21 6.8 MEDIUM 8.8 HIGH
OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.
CVE-2018-16732 1 Chshcms 1 Cscms 2024-11-21 6.8 MEDIUM 8.8 HIGH
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
CVE-2018-16650 1 Phpmyfaq 1 Phpmyfaq 2024-11-21 6.8 MEDIUM 8.8 HIGH
phpMyFAQ before 2.9.11 allows CSRF.
CVE-2018-16634 1 Pluck-cms 1 Pluck 2024-11-21 6.8 MEDIUM 8.8 HIGH
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
CVE-2018-16552 1 Micropyramid 1 Django Crm 2024-11-21 6.8 MEDIUM 8.8 HIGH
MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.
CVE-2018-16458 1 Baigo 1 Baigo Cms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article.
CVE-2018-16449 1 Onethink 1 Onethink 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.
CVE-2018-16448 1 Chshcms 1 Cscms 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save.
CVE-2018-16447 1 Frogcms Project 1 Frogcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
CVE-2018-16431 1 Yfcmf 1 Yfcmf 2024-11-21 6.8 MEDIUM 8.8 HIGH
admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.
CVE-2018-16416 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.
CVE-2018-16387 1 Elefantcms 1 Elefantcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.
CVE-2018-16380 1 Digimute 1 Ogma Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account.
CVE-2018-16366 1 Idreamsoft 1 Icms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
CVE-2018-16365 1 Idreamsoft 1 Icms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.