Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-03-13 CVE-2019-13395 Cross-Site Request Forgery (CSRF) vulnerability in Netgear Cg3700B Firmware 2.02.03
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs.
network
low complexity
netgear CWE-352
8.8
2020-03-13 CVE-2020-10540 Cross-Site Request Forgery (CSRF) vulnerability in Untis Webuntis
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
network
low complexity
untis CWE-352
8.8
2020-03-12 CVE-2019-17653 Cross-Site Request Forgery (CSRF) vulnerability in Fortinet Fortisiem 5.2.5
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.
network
low complexity
fortinet CWE-352
8.8
2020-03-12 CVE-2020-10504 Cross-Site Request Forgery (CSRF) vulnerability in Chadhaajay PHPkb 9.0
CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.
network
low complexity
chadhaajay CWE-352
4.3
2020-03-12 CVE-2020-10503 Cross-Site Request Forgery (CSRF) vulnerability in Chadhaajay PHPkb 9.0
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.
network
low complexity
chadhaajay CWE-352
4.3
2020-03-12 CVE-2020-10502 Cross-Site Request Forgery (CSRF) vulnerability in Chadhaajay PHPkb 9.0
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.
network
low complexity
chadhaajay CWE-352
4.3
2020-03-12 CVE-2020-10501 Cross-Site Request Forgery (CSRF) vulnerability in Chadhaajay PHPkb 9.0
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.
network
low complexity
chadhaajay CWE-352
6.5
2020-03-12 CVE-2020-10500 Cross-Site Request Forgery (CSRF) vulnerability in Chadhaajay PHPkb 9.0
CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to reply to any ticket, given the id, via a crafted request.
network
low complexity
chadhaajay CWE-352
4.3
2020-03-12 CVE-2020-10499 Cross-Site Request Forgery (CSRF) vulnerability in Chadhaajay PHPkb 9.0
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.
network
low complexity
chadhaajay CWE-352
4.3
2020-03-12 CVE-2020-10498 Cross-Site Request Forgery (CSRF) vulnerability in Chadhaajay PHPkb 9.0
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
network
low complexity
chadhaajay CWE-352
6.5