Vulnerabilities (CVE)

Filtered by CWE-352
Total 7389 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13477 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 MEDIUM 8.8 HIGH
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
CVE-2019-13401 1 Fortinet 2 Fcm-mb40, Fcm-mb40 Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
CVE-2019-13395 1 Netgear 2 Cg3700b, Cg3700b Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.
CVE-2019-13376 1 Phpbb 1 Phpbb 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
CVE-2019-13370 1 Ignitedcms 1 Ignitedcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
CVE-2019-13364 1 Piwigo 1 Piwigo 2024-11-21 6.8 MEDIUM 9.6 CRITICAL
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
CVE-2019-13363 1 Piwigo 1 Piwigo 2024-11-21 6.8 MEDIUM 9.6 CRITICAL
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit parameter. This is exploitable via CSRF.
CVE-2019-13199 1 Kyocera 2 Ecosys M5526cdw, Ecosys M5526cdw Firmware 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2019-13183 1 Flarum 1 Flarum 2024-11-21 6.8 MEDIUM 8.8 HIGH
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
CVE-2019-13170 1 Xerox 2 Phaser 3320, Phaser 3320 Firmware 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2019-13071 1 Cyberpowersystems 1 Powerpanel 2024-11-21 6.8 MEDIUM 8.8 HIGH
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.
CVE-2019-13056 1 Cyberpanel 1 Cyberpanel 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.
CVE-2019-12934 1 Wp-code-highlightjs Project 1 Wp-code-highlightjs 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
CVE-2019-12923 1 Mailenable 1 Mailenable 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.
CVE-2019-12922 2 Fedoraproject, Phpmyadmin 2 Fedora, Phpmyadmin 2024-11-21 5.8 MEDIUM 6.5 MEDIUM
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
CVE-2019-12851 1 Jetbrains 1 Youtrack 2024-11-21 6.8 MEDIUM 8.8 HIGH
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
CVE-2019-12836 1 Bobronix 1 Jeditor 2024-11-21 6.8 MEDIUM 8.8 HIGH
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request that can be invoked in the context of an authenticated user, leading to stealing of session tokens and account takeover.
CVE-2019-12826 1 Wpchef 1 Widget Logic 2024-11-21 6.8 MEDIUM 8.8 HIGH
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.
CVE-2019-12784 1 Verint 1 Impact 360 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them to guess and potentially compromise valid credentials without ever sending any traffic from their own machine to the target site.
CVE-2019-12769 1 Solarwinds 1 Serv-u Managed File Transfer 2024-11-21 6.8 MEDIUM 8.8 HIGH
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.