Vulnerabilities (CVE)

Filtered by CWE-352
Total 7480 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-10381 1 User Domain Whitelist Project 1 User Domain Whitelist 2024-11-21 6.8 MEDIUM 8.8 HIGH
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
CVE-2014-0594 1 Opensuse 1 Open Build Service 2024-11-21 6.8 MEDIUM 8.8 HIGH
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
CVE-2014-0197 1 Redhat 2 Cloudforms, Cloudforms Management Engine 2024-11-21 6.8 MEDIUM 8.8 HIGH
CFME: CSRF protection vulnerability via permissive check of the referrer header
CVE-2014-0026 1 Redhat 1 Subscription Asset Manager 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
katello-headpin is vulnerable to CSRF in REST API
CVE-2013-7476 1 Simple Fields Project 1 Simple Fields 2024-11-21 6.8 MEDIUM 8.8 HIGH
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
CVE-2013-7473 1 Windu 1 Windu Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
CVE-2013-7464 1 Csrf-magic Project 1 Csrf-magic 2024-11-21 6.8 MEDIUM 8.8 HIGH
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.
CVE-2013-7053 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
D-Link DIR-100 4.03B07: cli.cgi CSRF
CVE-2013-6811 1 D-link 2 Dsl6740u, Dsl6740u Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding, (2) Port Triggering Entries, (3) URL Filters in Parental Control, (4) Print Server settings, (5) QoS Queue Setup, or (6) QoS Classification Entries.
CVE-2013-6365 3 Debian, Horde, Opensuse 3 Debian Linux, Groupware, Opensuse 2024-11-21 2.6 LOW 5.3 MEDIUM
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
CVE-2013-6364 2 Debian, Horde 2 Debian Linux, Groupware 2024-11-21 6.8 MEDIUM 8.8 HIGH
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
CVE-2013-6275 2 Debian, Horde 2 Debian Linux, Groupware 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
CVE-2013-4865 1 Micasaverde 2 Veralite, Veralite Firmware 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
CVE-2013-4848 1 Tp-link 2 Tl-wdr4300, Tl-wdr4300 Firmware 2024-11-21 9.3 HIGH 8.8 HIGH
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
CVE-2013-4792 1 Prestashop 1 Prestashop 2024-11-21 3.5 LOW 5.5 MEDIUM
PrestaShop before 1.4.11 allows logout CSRF.
CVE-2013-4665 1 Spbas 1 Business Automation Software 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
SPBAS Business Automation Software 2012 has CSRF.
CVE-2013-4227 1 Mozilla 1 Persona 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.
CVE-2013-3935 1 Opsview 2 Opsview, Opsview Core 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.
CVE-2013-3568 1 Cisco 2 Linksys Wrt110, Linksys Wrt110 Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
CVE-2013-3516 1 Netgear 4 Wnr3500l, Wnr3500l Firmware, Wnr3500u and 1 more 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.