Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-03-23 CVE-2015-8624 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.
network
low complexity
mediawiki CWE-352
8.8
2017-03-23 CVE-2015-8623 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.
network
low complexity
mediawiki CWE-352
8.8
2017-03-23 CVE-2016-5758 Cross-Site Request Forgery (CSRF) vulnerability in Netiq Access Manager 4.1/4.2
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
network
low complexity
netiq CWE-352
8.8
2017-03-22 CVE-2017-5874 Cross-Site Request Forgery (CSRF) vulnerability in D-Link Dir-600M Firmware
CSRF exists on D-Link DIR-600M Rev.
network
low complexity
d-link CWE-352
8.8
2017-03-21 CVE-2016-4504 Cross-Site Request Forgery (CSRF) vulnerability in Meteocontrol Weblog
A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions.
network
low complexity
meteocontrol CWE-352
8.8
2017-03-20 CVE-2016-4928 Cross-Site Request Forgery (CSRF) vulnerability in Juniper Junos Space
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
network
low complexity
juniper CWE-352
8.8
2017-03-20 CVE-2017-6803 Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds FTP Voyager 16.2.0
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.
network
low complexity
solarwinds CWE-352
8.8
2017-03-18 CVE-2017-7178 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
CSRF was discovered in the web UI in Deluge before 1.3.14.
network
low complexity
deluge-torrent debian CWE-352
8.8
2017-03-17 CVE-2017-3877 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Communications Manager 11.5(1.11.007.2)
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software.
network
low complexity
cisco CWE-352
6.5
2017-03-17 CVE-2017-0045 Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Windows 7, Windows Server 2008 and Windows Vista
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."
local
low complexity
microsoft CWE-352
5.5