Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-08-14 CVE-2018-7097 Cross-Site Request Forgery (CSRF) vulnerability in HP 3Par Service Provider Sp4.2.0/Sp4.3.0/Sp4.4.0
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7).
network
low complexity
hp CWE-352
8.8
2018-08-10 CVE-2018-14783 Cross-Site Request Forgery (CSRF) vulnerability in Netcommwireless Nwl-25 Firmware 2.0.29.11
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior.
network
low complexity
netcommwireless CWE-352
8.8
2018-08-10 CVE-2018-15187 Cross-Site Request Forgery (CSRF) vulnerability in Advanced Real Estate Script Project Advanced Real Estate Script 4.0.9
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
8.0
2018-08-10 CVE-2018-15186 Cross-Site Request Forgery (CSRF) vulnerability in Chartered Accountant : Auditor Website Project Chartered Accountant : Auditor Website 2.0.1
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.
network
low complexity
chartered-accountant CWE-352
8.8
2018-08-08 CVE-2018-15203 Cross-Site Request Forgery (CSRF) vulnerability in Ignitedcms 1.0.0/1.0.1/20170219
An issue was discovered in Ignited CMS through 2017-02-19.
network
low complexity
ignitedcms CWE-352
6.5
2018-08-08 CVE-2018-15202 Cross-Site Request Forgery (CSRF) vulnerability in Juunan06 Ecommerce 20180805
An issue was discovered in Juunan06 eCommerce through 2018-08-05.
network
low complexity
juunan06 CWE-352
6.3
2018-08-08 CVE-2018-15198 Cross-Site Request Forgery (CSRF) vulnerability in Onethink 1.1
An issue was discovered in OneThink v1.1.
network
low complexity
onethink CWE-352
8.8
2018-08-08 CVE-2018-15197 Cross-Site Request Forgery (CSRF) vulnerability in Onethink 1.1
An issue was discovered in OneThink v1.1.
network
low complexity
onethink CWE-352
8.8
2018-08-08 CVE-2018-15193 Cross-Site Request Forgery (CSRF) vulnerability in Gogs 0.11.53
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
network
low complexity
gogs CWE-352
8.8
2018-08-08 CVE-2018-15177 Cross-Site Request Forgery (CSRF) vulnerability in Gxlcms 2.0
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
network
low complexity
gxlcms CWE-352
8.8