Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-04-09 CVE-2020-21884 Cross-Site Request Forgery (CSRF) vulnerability in Indionetworks products
Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.
network
low complexity
indionetworks CWE-352
8.8
2021-04-08 CVE-2021-22512 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Application Automation Tools
Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin.
network
low complexity
microfocus CWE-352
6.5
2021-04-08 CVE-2020-23426 Cross-Site Request Forgery (CSRF) vulnerability in Zzcms 201910
zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.
network
low complexity
zzcms CWE-352
critical
9.8
2021-04-08 CVE-2021-30114 Cross-Site Request Forgery (CSRF) vulnerability in Web-School Enterprise Resource Planning 5.0
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create.
network
low complexity
web-school CWE-352
6.5
2021-04-08 CVE-2021-30112 Cross-Site Request Forgery (CSRF) vulnerability in Web-School Enterprise Resource Planning 5.0
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create.
network
low complexity
web-school CWE-352
6.5
2021-04-07 CVE-2021-21641 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Promoted Builds
A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.
network
low complexity
jenkins CWE-352
4.3
2021-04-07 CVE-2021-20687 Cross-Site Request Forgery (CSRF) vulnerability in Daifukuya Kagemai 0.8.8
Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
daifukuya CWE-352
8.8
2021-04-07 CVE-2021-30147 Cross-Site Request Forgery (CSRF) vulnerability in Dmasoftlab Radius Manager 4.4.0
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
network
low complexity
dmasoftlab CWE-352
8.8
2021-04-05 CVE-2021-24173 Cross-Site Request Forgery (CSRF) vulnerability in VM Backups Project VM Backups 1.0
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.
network
low complexity
vm-backups-project CWE-352
6.1
2021-04-05 CVE-2021-24172 Cross-Site Request Forgery (CSRF) vulnerability in VM Backups Project VM Backups 1.0
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .
network
low complexity
vm-backups-project CWE-352
4.3