Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-10-13 CVE-2016-1261 Cross-Site Request Forgery (CSRF) vulnerability in Juniper Junos
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).
network
low complexity
juniper CWE-352
8.8
2017-10-13 CVE-2016-5789 Cross-Site Request Forgery (CSRF) vulnerability in Jantek Jtc-200 Firmware
A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions.
network
low complexity
jantek CWE-352
8.0
2017-10-06 CVE-2015-2143 Cross-Site Request Forgery (CSRF) vulnerability in PHPbugtracker Project PHPbugtracker
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecified impact via unknown parameters.
network
low complexity
phpbugtracker-project CWE-352
8.8
2017-10-06 CVE-2015-2142 Cross-Site Request Forgery (CSRF) vulnerability in PHPbugtracker Project PHPbugtracker
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for requests that cause an unspecified impact via the id parameter to project.php, (2) hijack the authentication of users for requests that cause an unspecified impact via the group_id parameter to group.php, (3) hijack the authentication of users for requests that delete statuses via the status_id parameter to status.php, (4) hijack the authentication of users for requests that delete severities via the severity_id parameter to severity.php, (5) hijack the authentication of users for requests that cause an unspecified impact via the priority_id parameter to priority.php, (6) hijack the authentication of users for requests that delete the operating system via the os_id parameter to os.php, (7) hijack the authentication of users for requests that delete databases via the database_id parameter to database.php, or (8) hijack the authentication of users for requests that delete sites via the site_id parameter to sites.php.
network
low complexity
phpbugtracker-project CWE-352
8.0
2017-10-06 CVE-2017-15084 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Metasploit
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
network
low complexity
rapid7 CWE-352
6.5
2017-10-06 CVE-2017-15063 Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error.
network
low complexity
intelliants CWE-352
8.8
2017-10-05 CVE-2017-1000093 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Poll SCM
Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks.
network
low complexity
jenkins CWE-352
8.8
2017-10-05 CVE-2017-1000092 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins GIT
Git Plugin connects to a user-specified Git repository as part of form validation.
network
high complexity
jenkins CWE-352
7.5
2017-10-05 CVE-2017-1000091 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Github Branch Source
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g.
network
low complexity
jenkins CWE-352
6.3
2017-10-05 CVE-2017-1000090 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Role-Based Authorization Strategy
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks.
network
low complexity
jenkins CWE-352
8.8