Vulnerabilities (CVE)

Filtered by CWE-352
Total 7407 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-9958 1 Quadbase 1 Espressreport Enterprise Server 2024-11-21 6.8 MEDIUM 8.8 HIGH
CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.
CVE-2019-9926 1 Labkey 1 Labkey Server 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability.
CVE-2019-9883 1 Hgiga 8 Msr35 Isherlock-base, Msr35 Isherlock-sysinfo, Msr35 Isherlock-user and 5 more 2024-11-21 6.8 MEDIUM 8.8 HIGH
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.
CVE-2019-9882 1 Hgiga 8 Msr35 Isherlock-base, Msr35 Isherlock-sysinfo, Msr35 Isherlock-user and 5 more 2024-11-21 6.8 MEDIUM 8.8 HIGH
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.
CVE-2019-9787 1 Wordpress 1 Wordpress 2024-11-21 6.8 MEDIUM 8.8 HIGH
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.
CVE-2019-9769 1 Kartatopia 1 Piluscart 2024-11-21 6.8 MEDIUM 8.8 HIGH
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.
CVE-2019-9688 1 Sftnow 1 Sftnow 2024-11-21 6.8 MEDIUM 8.8 HIGH
sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.
CVE-2019-9652 1 Sdcms 1 Sdcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the t2 parameter.
CVE-2019-9625 1 Directadmin 1 Directadmin 2024-11-21 6.8 MEDIUM 8.8 HIGH
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
CVE-2019-9604 1 Online Lottery Php Readymade Script Project 1 Online Lottery Php Readymade Script 2024-11-21 6.8 MEDIUM 8.8 HIGH
PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.
CVE-2019-9603 1 1234n 1 Minicms 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-2018-18891.
CVE-2019-9598 1 Chshcms 1 Cscms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
CVE-2019-9597 1 Darktrace 1 Enterprise Immune System 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
CVE-2019-9596 1 Darktrace 1 Enterprise Immune System 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
CVE-2019-9549 1 Popojicms 1 Popojicms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.
CVE-2019-9231 1 Audiocodes 8 Mediant 500-mbsr, Mediant 500-mbsr Firmware, Mediant 500l-msbr and 5 more 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.
CVE-2019-9182 1 Zzzcms 1 Zzzphp 2024-11-21 6.8 MEDIUM 8.8 HIGH
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.
CVE-2019-9176 1 Gitlab 1 Gitlab 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF.
CVE-2019-9062 1 Phpscriptsmall 1 Online Food Ordering Script 2024-11-21 6.0 MEDIUM 8.0 HIGH
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
CVE-2019-9052 1 Pluck-cms 1 Pluck 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?action=deleteimage&var1= URI.