Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-02-20 CVE-2018-6941 Cross-Site Request Forgery (CSRF) vulnerability in Nat32 2.2
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.
network
low complexity
nat32 CWE-352
8.8
2018-02-19 CVE-2018-7219 Cross-Site Request Forgery (CSRF) vulnerability in 5None Nonecms 1.3.0
application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request.
network
low complexity
5none CWE-352
8.8
2018-02-19 CVE-2017-16756 Cross-Site Request Forgery (CSRF) vulnerability in Userscape Helpspot
An issue was discovered in Userscape HelpSpot before 4.7.2.
network
low complexity
userscape CWE-352
8.8
2018-02-18 CVE-2018-7216 Cross-Site Request Forgery (CSRF) vulnerability in Tejari Bravo Solution
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated users to hijack the authentication of application users for requests that modify their personal data by leveraging lack of anti-CSRF tokens.
network
low complexity
tejari CWE-352
8.0
2018-02-16 CVE-2018-7176 Cross-Site Request Forgery (CSRF) vulnerability in Frontaccounting 2.4.3
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).
network
low complexity
frontaccounting CWE-352
8.8
2018-02-15 CVE-2017-5796 Cross-Site Request Forgery (CSRF) vulnerability in HP products
A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.
network
low complexity
hp CWE-352
8.8
2018-02-15 CVE-2017-5781 Cross-Site Request Forgery (CSRF) vulnerability in HP Matrix Operating Environment 7.6
A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.
network
low complexity
hp CWE-352
8.8
2018-02-15 CVE-2016-8513 Cross-Site Request Forgery (CSRF) vulnerability in HP Version Control Repository Manager
A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found.
network
low complexity
hp CWE-352
8.0
2018-02-12 CVE-2017-9963 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric Powerscada Anywhere 1.0
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests.
network
low complexity
schneider-electric CWE-352
8.1
2018-02-12 CVE-2018-6888 Cross-Site Request Forgery (CSRF) vulnerability in Typesettercms Typesetter 5.1
An issue was discovered in Typesetter 5.1.
network
low complexity
typesettercms CWE-352
8.0