Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-02-24 CVE-2016-9975 Cross-Site Request Forgery (CSRF) vulnerability in IBM Dashboard Application Services HUB 3.1.2.1/3.1.3
IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2017-02-21 CVE-2017-6127 Cross-Site Request Forgery (CSRF) vulnerability in Digisol Dg-Hr1400 Firmware 1.00.02
Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow remote attackers to hijack the authentication of administrators for requests that (1) change the SSID, (2) change the Wi-Fi password, or (3) possibly have unspecified other impact via crafted requests to form2WlanBasicSetup.cgi.
network
low complexity
digisol CWE-352
8.8
2017-02-21 CVE-2017-5959 Cross-Site Request Forgery (CSRF) vulnerability in Metalgenix Genixcms
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges.
network
low complexity
metalgenix CWE-352
critical
9.8
2017-02-17 CVE-2016-4315 Cross-Site Request Forgery (CSRF) vulnerability in Wso2 Carbon 4.4.5
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.
network
low complexity
wso2 CWE-352
5.7
2017-02-17 CVE-2016-4311 Cross-Site Request Forgery (CSRF) vulnerability in Wso2 Identity Server 5.1.0
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.
network
low complexity
wso2 CWE-352
8.8
2017-02-15 CVE-2016-6033 Cross-Site Request Forgery (CSRF) vulnerability in IBM products
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2017-02-13 CVE-2017-5169 Cross-Site Request Forgery (CSRF) vulnerability in Hanwha-Security Smart Security Manager 1.5
An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior.
network
high complexity
hanwha-security CWE-352
7.5
2017-02-13 CVE-2017-5165 Cross-Site Request Forgery (CSRF) vulnerability in Binom3 Universal Multifunctional Electric Power Quality Meter Firmware
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter.
network
low complexity
binom3 CWE-352
7.6
2017-02-13 CVE-2017-5145 Cross-Site Request Forgery (CSRF) vulnerability in Carlosgavazzi Vmu-C EM Firmware and Vmu-C PV Firmware
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17.
network
low complexity
carlosgavazzi CWE-352
critical
10.0
2017-02-13 CVE-2016-9365 Cross-Site Request Forgery (CSRF) vulnerability in Moxa products
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4.
network
low complexity
moxa CWE-352
8.8