Vulnerabilities (CVE)

Filtered by CWE-352
Total 7373 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16447 1 Frogcms Project 1 Frogcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
CVE-2018-16431 1 Yfcmf 1 Yfcmf 2024-11-21 6.8 MEDIUM 8.8 HIGH
admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.
CVE-2018-16416 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.
CVE-2018-16387 1 Elefantcms 1 Elefantcms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.
CVE-2018-16380 1 Digimute 1 Ogma Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account.
CVE-2018-16366 1 Idreamsoft 1 Icms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
CVE-2018-16365 1 Idreamsoft 1 Icms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
CVE-2018-16345 1 Easycms 1 Easycms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent.
CVE-2018-16339 1 Phome 1 Empirecms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
CVE-2018-16338 1 Auracms 1 Auracms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.
CVE-2018-16337 1 Chshcms 1 Cscms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.
CVE-2018-16332 1 Idreamsoft 1 Icms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
CVE-2018-16331 1 Damicms 1 Damicms 2024-11-21 6.8 MEDIUM 8.8 HIGH
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
CVE-2018-16315 1 Bijiadao 1 Waimai Super Cms 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
CVE-2018-16314 1 Icmsdev 1 Icms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.php substring in this header.
CVE-2018-16218 1 Yealink 2 Ultra-elegant Ip Phone Sip-t41p, Ultra-elegant Ip Phone Sip-t41p Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
A CSRF (Cross Site Request Forgery) in the web interface of the Yeahlink Ultra-elegant IP Phone SIP-T41P firmware version 66.83.0.35 allows a remote attacker to trigger code execution or settings modification on the device by providing a crafted link to the victim.
CVE-2018-16136 1 Ipbrick 1 Ipbrick Os 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission of multiple forms unwillingly by a victim.
CVE-2018-15901 1 E107 1 E107 2024-11-21 6.8 MEDIUM 8.8 HIGH
e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.
CVE-2018-15884 1 Ricoh 2 Mp C4504ex, Mp C4504ex Firmware 2024-11-21 6.8 MEDIUM 8.8 HIGH
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
CVE-2018-15851 1 Flexocms Project 1 Flexo Cms 2024-11-21 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add.