Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2011-5250 Cross-Site Request Forgery (CSRF) vulnerability in Prophecyinternational Snare
Snare for Linux before 1.7.0 has CSRF in the web interface.
network
low complexity
prophecyinternational CWE-352
6.5
2020-01-05 CVE-2019-20077 Cross-Site Request Forgery (CSRF) vulnerability in Typesettercms Typesetter 5.1
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability.
network
low complexity
typesettercms CWE-352
4.3
2020-01-03 CVE-2014-5516 Cross-Site Request Forgery (CSRF) vulnerability in Konakart
Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a user email address via an unspecified GET request.
network
low complexity
konakart CWE-352
6.5
2020-01-02 CVE-2014-3590 Cross-Site Request Forgery (CSRF) vulnerability in Redhat Satellite 6.0
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action.
network
low complexity
redhat CWE-352
6.5
2020-01-02 CVE-2013-3935 Cross-Site Request Forgery (CSRF) vulnerability in Opsview and Opsview Core
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.
network
low complexity
opsview CWE-352
8.8
2019-12-31 CVE-2015-5595 Cross-Site Request Forgery (CSRF) vulnerability in Zenphoto
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).
network
low complexity
zenphoto CWE-352
6.5
2019-12-31 CVE-2019-12273 Cross-Site Request Forgery (CSRF) vulnerability in Outsystems
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads.
network
low complexity
outsystems CWE-352
6.5
2019-12-30 CVE-2013-0196 Cross-Site Request Forgery (CSRF) vulnerability in Redhat Openshift 1.2
A CSRF issue was found in OpenShift Enterprise 1.2.
network
low complexity
redhat CWE-352
6.5
2019-12-30 CVE-2019-19737 Cross-Site Request Forgery (CSRF) vulnerability in Mfscripts Yetishare
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.
network
low complexity
mfscripts CWE-352
8.8
2019-12-30 CVE-2019-20071 Cross-Site Request Forgery (CSRF) vulnerability in Netis-Systems Dl4343 Firmware
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
network
low complexity
netis-systems CWE-352
6.5