Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-02-19 CVE-2017-16756 Cross-Site Request Forgery (CSRF) vulnerability in Userscape Helpspot
An issue was discovered in Userscape HelpSpot before 4.7.2.
network
low complexity
userscape CWE-352
8.8
2018-02-18 CVE-2018-7216 Cross-Site Request Forgery (CSRF) vulnerability in Tejari Bravo Solution
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated users to hijack the authentication of application users for requests that modify their personal data by leveraging lack of anti-CSRF tokens.
network
low complexity
tejari CWE-352
8.0
2018-02-16 CVE-2018-7176 Cross-Site Request Forgery (CSRF) vulnerability in Frontaccounting 2.4.3
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).
network
low complexity
frontaccounting CWE-352
8.8
2018-02-15 CVE-2017-5796 Cross-Site Request Forgery (CSRF) vulnerability in HP products
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.
network
low complexity
hp CWE-352
8.8
2018-02-15 CVE-2017-5781 Cross-Site Request Forgery (CSRF) vulnerability in HP Matrix Operating Environment 7.6
A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.
network
low complexity
hp CWE-352
8.8
2018-02-15 CVE-2016-8513 Cross-Site Request Forgery (CSRF) vulnerability in HP Version Control Repository Manager
A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found.
network
low complexity
hp CWE-352
8.0
2018-02-12 CVE-2017-9963 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric Powerscada Anywhere 1.0
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests.
network
low complexity
schneider-electric CWE-352
8.1
2018-02-12 CVE-2018-6888 Cross-Site Request Forgery (CSRF) vulnerability in Typesettercms Typesetter 5.1
An issue was discovered in Typesetter 5.1.
network
low complexity
typesettercms CWE-352
8.0
2018-02-09 CVE-2018-1000053 Cross-Site Request Forgery (CSRF) vulnerability in Limesurvey 3.0.0
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable.
network
low complexity
limesurvey CWE-352
8.8
2018-02-07 CVE-2017-17552 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Manageengine Admanager Plus
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
network
low complexity
zohocorp CWE-352
8.8