Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-04-18 CVE-2019-10300 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Gitlab
A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
8.0
2019-04-18 CVE-2018-17168 Cross-Site Request Forgery (CSRF) vulnerability in Printeron 4.1.4
PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page.
network
low complexity
printeron CWE-352
6.5
2019-04-18 CVE-2019-1797 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Wireless LAN Controller Software
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device configuration.
network
low complexity
cisco CWE-352
8.8
2019-04-18 CVE-2019-1722 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system.
network
low complexity
cisco CWE-352
6.5
2019-04-17 CVE-2019-10642 Cross-Site Request Forgery (CSRF) vulnerability in Contao CMS 4.7.0
Contao 4.7 allows CSRF.
network
low complexity
contao CWE-352
8.8
2019-04-17 CVE-2019-9176 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1.
network
low complexity
gitlab CWE-352
6.5
2019-04-17 CVE-2018-13810 Cross-Site Request Forgery (CSRF) vulnerability in Siemens CP 1604 Firmware and CP 1616 Firmware
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions).
network
low complexity
siemens CWE-352
6.5
2019-04-15 CVE-2018-16966 Cross-Site Request Forgery (CSRF) vulnerability in Filemanagerpro File Manager 3.0
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
network
low complexity
filemanagerpro CWE-352
8.8
2019-04-15 CVE-2018-17584 Cross-Site Request Forgery (CSRF) vulnerability in Wpfastestcache WP Fastest Cache 0.8.8.5
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
network
low complexity
wpfastestcache CWE-352
8.8
2019-04-15 CVE-2017-18366 Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.1.5
Subrion CMS 4.1.5 has CSRF in blog/delete/.
network
low complexity
intelliants CWE-352
8.8