Show filters
1,744 Total Results
Displaying 101-110 of 1,744
Sort by:
Attacker Value
Unknown
CVE-2022-4349
Disclosure Date: December 08, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file delete.html. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215109 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-44849
Disclosure Date: December 07, 2022 (last updated February 24, 2025)
A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.
0
Attacker Value
Unknown
CVE-2022-23475
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped variable reflected in the DOM on line 116. This issue has been addressed in commit `ec3b4a419e`. Users are advised to manually apply the commit in order to mitigate this issue. Users may also mitigate this issue with in two parts 1) The CSRF vulnerability can be mitigated by making the daloRadius session cookie to samesite=Lax or by the implimentation of a CSRF token in all forms. 2) The XSS vulnerability may be mitigated by escaping it or by introducing a Content-Security policy.
0
Attacker Value
Unknown
CVE-2022-3926
Disclosure Date: December 05, 2022 (last updated February 24, 2025)
The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID
0
Attacker Value
Unknown
CVE-2022-45824
Disclosure Date: December 05, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-43470
Disclosure Date: December 05, 2022 (last updated February 24, 2025)
Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F FS030W software versions v3.3.5 and earlier, and +F FS040W software versions v1.4.1 and earlier allows an adjacent attacker to hijack the authentication of an administrator and user's unintended operations such as to reboot the product and/or reset the configuration to the initial set-up may be performed.
0
Attacker Value
Unknown
CVE-2022-35730
Disclosure Date: December 04, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Oceanwp sticky header plugin <= 1.0.8 on WordPress.
0
Attacker Value
Unknown
CVE-2022-45668
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
0
Attacker Value
Unknown
CVE-2022-45667
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
0
Attacker Value
Unknown
CVE-2022-45674
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
0