Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-03-27 CVE-2017-6066 Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.0.5
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/.
network
low complexity
intelliants CWE-352
8.8
2017-03-27 CVE-2017-6002 Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.0.5.10
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/.
network
low complexity
intelliants CWE-352
8.8
2017-03-23 CVE-2015-8624 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.
network
low complexity
mediawiki CWE-352
8.8
2017-03-23 CVE-2015-8623 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.
network
low complexity
mediawiki CWE-352
8.8
2017-03-23 CVE-2016-5758 Cross-Site Request Forgery (CSRF) vulnerability in Netiq Access Manager 4.1/4.2
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
network
low complexity
netiq CWE-352
8.8
2017-03-22 CVE-2017-5874 Cross-Site Request Forgery (CSRF) vulnerability in D-Link Dir-600M Firmware
CSRF exists on D-Link DIR-600M Rev.
network
low complexity
d-link CWE-352
8.8
2017-03-21 CVE-2016-4504 Cross-Site Request Forgery (CSRF) vulnerability in Meteocontrol Weblog
A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions.
network
low complexity
meteocontrol CWE-352
8.8
2017-03-20 CVE-2016-4928 Cross-Site Request Forgery (CSRF) vulnerability in Juniper Junos Space
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
network
low complexity
juniper CWE-352
8.8
2017-03-20 CVE-2017-6803 Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds FTP Voyager 16.2.0
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.
network
low complexity
solarwinds CWE-352
8.8
2017-03-18 CVE-2017-7178 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
CSRF was discovered in the web UI in Deluge before 1.3.14.
network
low complexity
deluge-torrent debian CWE-352
8.8