Vulnerabilities (CVE)

Filtered by CWE-352
Total 7480 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19911 1 Freeswitch 1 Freeswitch 2024-11-21 7.6 HIGH 7.5 HIGH
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as demonstrated by an api/system?calc URI. This can also be exploited via CSRF. Alternatively, the default password of works for the freeswitch account can sometimes be used.
CVE-2018-19829 1 Artica 1 Integria Ims 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.
CVE-2018-19621 1 Showdoc 1 Showdoc 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
CVE-2018-19613 1 Westermo 6 Dr-250, Dr-250 Firmware, Dr-260 and 3 more 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
CVE-2018-19561 1 Sikcms 1 Sikcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.
CVE-2018-19560 1 Bagesoft 1 Bagecms 2024-11-21 9.3 HIGH 8.8 HIGH
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
CVE-2018-19555 1 Tp4a 1 Teleport 2024-11-21 6.8 MEDIUM 8.8 HIGH
tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.
CVE-2018-19546 1 Jtbc 1 Jtbc Php 2024-11-21 6.8 MEDIUM 8.8 HIGH
JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.
CVE-2018-19545 1 Jeecms 1 Jeecms 2024-11-21 6.8 MEDIUM 8.8 HIGH
JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.
CVE-2018-19544 1 Jeecms 1 Jeecms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.
CVE-2018-19525 1 Systrome 6 Cumilon Isg-600c, Cumilon Isg-600c Firmware, Cumilon Isg-600h and 3 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of csrf token validation.
CVE-2018-19511 1 Ens 1 Webgalamb 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator password.
CVE-2018-19376 1 Greencms 1 Greencms 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI.
CVE-2018-19335 1 Google 1 Monorail 2024-11-21 2.6 LOW 5.3 MEDIUM
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.
CVE-2018-19334 1 Google 1 Monorail 2024-11-21 4.3 MEDIUM 5.3 MEDIUM
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.
CVE-2018-19332 1 S-cms 1 S-cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.
CVE-2018-19327 1 Jtbc 1 Jtbc Php 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.
CVE-2018-19319 1 Srcms Project 1 Srcms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
CVE-2018-19318 1 Srcms Project 1 Srcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.
CVE-2018-19291 1 Dilicms 1 Dilicms 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.