Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-07-02 CVE-2018-12529 Cross-Site Request Forgery (CSRF) vulnerability in Intex N150 Firmware
An issue was discovered on Intex N150 devices.
network
low complexity
intex CWE-352
8.8
2018-07-01 CVE-2018-13040 Cross-Site Request Forgery (CSRF) vulnerability in Opendesa Opensid 18.06Pasca
OpenSID 18.06-pasca has a CSRF vulnerability.
network
low complexity
opendesa CWE-352
8.8
2018-07-01 CVE-2018-13032 Cross-Site Request Forgery (CSRF) vulnerability in Ecessa Shieldlink Sl175Ehq Firmware 10.7.4
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.
network
low complexity
ecessa CWE-352
8.8
2018-06-29 CVE-2018-13010 Cross-Site Request Forgery (CSRF) vulnerability in Wstmall 1.9.1170316
WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account.
network
low complexity
wstmall CWE-352
8.8
2018-06-29 CVE-2018-12971 Cross-Site Request Forgery (CSRF) vulnerability in Easycms 1.3
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
network
low complexity
easycms CWE-352
6.5
2018-06-26 CVE-2018-11447 Cross-Site Request Forgery (CSRF) vulnerability in Siemens Scalance M875 Firmware
A vulnerability has been identified in SCALANCE M875 (All versions).
network
low complexity
siemens CWE-352
8.8
2018-06-26 CVE-2018-1000514 Cross-Site Request Forgery (CSRF) vulnerability in Limesurvey 3.0.0
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result in CSRF admins to delete boxes.
network
low complexity
limesurvey CWE-352
4.3
2018-06-26 CVE-2018-1000507 Cross-Site Request Forgery (CSRF) vulnerability in JJJ WP User Groups 2.0.0
WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types.
network
low complexity
jjj CWE-352
6.5
2018-06-26 CVE-2018-1000506 Cross-Site Request Forgery (CSRF) vulnerability in Mediaron Metronet TAG Manager 1.2.7
Metronet Tag Manager version 1.2.7 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page /wp-admin/options-general.php?page=metronet-tag-manager that can result in allows anybody to do almost anything an admin can.
network
low complexity
mediaron CWE-352
8.8
2018-06-26 CVE-2018-1000505 Cross-Site Request Forgery (CSRF) vulnerability in Tooltipy 5.0
Tooltipy (tooltips for WP) version 5 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in could allow anybody to duplicate posts.
network
low complexity
tooltipy CWE-352
6.5