Vulnerabilities > Cross-Site Request Forgery (CSRF)
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-02-21 | CVE-2018-7308 | Cross-Site Request Forgery (CSRF) vulnerability in Hosting Project Hosting 20180211 A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account. | 8.8 |
2018-02-21 | CVE-2018-7305 | Cross-Site Request Forgery (CSRF) vulnerability in Mybb 1.8.14 MyBB 1.8.14 is not checking for a valid CSRF token, leading to arbitrary deletion of user accounts. | 4.9 |
2018-02-21 | CVE-2016-0348 | Cross-Site Request Forgery (CSRF) vulnerability in IBM Tririga Application Platform Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | 8.0 |
2018-02-20 | CVE-2017-12415 | Cross-Site Request Forgery (CSRF) vulnerability in Oxid-Esales Eshop OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), and Professional Edition before 6.0.0 RC2 (development), 4.9.x before 4.9.10 (legacy) and 4.10.x before 4.10.5 (maintenance) allow remote attackers to hijack the cart session of a client via Cross-Site Request Forgery (CSRF) if the following pre-conditions are met: (1) the attacker knows which shop is presently used by the client, (2) the attacker knows the exact time when the customer will add product items to the cart, (3) the attacker knows which product items are already in the cart (has to know their article IDs), and (4) the attacker would be able to trick user into clicking a button (submit form) of an e-mail or remote site within the period of visiting the shop and placing an order. | 7.5 |
2018-02-20 | CVE-2018-6941 | Cross-Site Request Forgery (CSRF) vulnerability in Nat32 2.2 A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS. | 8.8 |
2018-02-19 | CVE-2018-7219 | Cross-Site Request Forgery (CSRF) vulnerability in 5None Nonecms 1.3.0 application/admin/controller/Admin.php in NoneCms 1.3.0 has CSRF, as demonstrated by changing an admin password or adding an account via a public/index.php/admin/admin/edit.html request. | 8.8 |
2018-02-19 | CVE-2017-16756 | Cross-Site Request Forgery (CSRF) vulnerability in Userscape Helpspot An issue was discovered in Userscape HelpSpot before 4.7.2. | 8.8 |
2018-02-18 | CVE-2018-7216 | Cross-Site Request Forgery (CSRF) vulnerability in Tejari Bravo Solution Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated users to hijack the authentication of application users for requests that modify their personal data by leveraging lack of anti-CSRF tokens. | 8.0 |
2018-02-16 | CVE-2018-7176 | Cross-Site Request Forgery (CSRF) vulnerability in Frontaccounting 2.4.3 FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page). | 8.8 |
2018-02-15 | CVE-2017-5796 | Cross-Site Request Forgery (CSRF) vulnerability in HP products A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found. | 8.8 |