Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-02-16 CVE-2018-7176 Cross-Site Request Forgery (CSRF) vulnerability in Frontaccounting 2.4.3
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).
network
low complexity
frontaccounting CWE-352
8.8
2018-02-15 CVE-2017-5796 Cross-Site Request Forgery (CSRF) vulnerability in HP products
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.
network
low complexity
hp CWE-352
8.8
2018-02-15 CVE-2017-5781 Cross-Site Request Forgery (CSRF) vulnerability in HP Matrix Operating Environment 7.6
A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.
network
low complexity
hp CWE-352
8.8
2018-02-15 CVE-2016-8513 Cross-Site Request Forgery (CSRF) vulnerability in HP Version Control Repository Manager
A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found.
network
low complexity
hp CWE-352
8.0
2018-02-12 CVE-2017-9963 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric Powerscada Anywhere 1.0
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests.
network
low complexity
schneider-electric CWE-352
8.1
2018-02-12 CVE-2018-6888 Cross-Site Request Forgery (CSRF) vulnerability in Typesettercms Typesetter 5.1
An issue was discovered in Typesetter 5.1.
network
low complexity
typesettercms CWE-352
8.0
2018-02-09 CVE-2018-1000053 Cross-Site Request Forgery (CSRF) vulnerability in Limesurvey 3.0.0
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable.
network
low complexity
limesurvey CWE-352
8.8
2018-02-07 CVE-2017-17552 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Manageengine Admanager Plus
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
network
low complexity
zohocorp CWE-352
8.8
2018-02-06 CVE-2014-5280 Cross-Site Request Forgery (CSRF) vulnerability in Boot2Docker
boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication.
network
low complexity
boot2docker CWE-352
8.8
2018-02-06 CVE-2018-6288 Cross-Site Request Forgery (CSRF) vulnerability in Kaspersky Secure Mail Gateway 1.1
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
network
low complexity
kaspersky CWE-352
8.8