Show filters
1,941 Total Results
Displaying 121-130 of 1,941
Sort by:
Attacker Value
Unknown

CVE-2023-25170

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation. The problem is fixed in version 8.0.1.
Attacker Value
Unknown

CVE-2023-25973

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.
Attacker Value
Unknown

CVE-2023-23711

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in A2 Hosting A2 Optimized WP plugin <= 3.0.4 versions.
Attacker Value
Unknown

CVE-2023-22700

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 9.3.0 versions.
Attacker Value
Unknown

CVE-2023-25991

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
Attacker Value
Unknown

CVE-2022-47440

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Tickets plugin <= 1.9.10 versions.
Attacker Value
Unknown

CVE-2022-47166

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
Attacker Value
Unknown

CVE-2016-15028

Disclosure Date: March 12, 2023 (last updated February 24, 2025)
A vulnerability was found in ICEPAY REST-API-NET 0.9. It has been declared as problematic. Affected by this vulnerability is the function RestClient of the file Classes/RestClient.cs of the component Checksum Validation. The manipulation leads to improper validation of integrity check value. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 1.0 is able to address this issue. The patch is named 61f6b8758e5c971abff5f901cfa9f231052b775f. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222847.
Attacker Value
Unknown

CVE-2023-1205

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.
Attacker Value
Unknown

CVE-2023-27490

Disclosure Date: March 09, 2023 (last updated February 24, 2025)
NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A bad actor who can read traffic on the victim's network or who is able to social engineer the victim to click a manipulated login link could intercept and tamper with the authorization URL to **log in as the victim**, bypassing the CSRF protection. This is due to a partial failure during a compromised OAuth session where a session code is erroneously generated. This issue has been addressed in version 4.20.1. Users are advised to upgrade. Users unable to upgrade may using Advanced Initialization, manually check the callback request for state, pkce, and nonce against the provider configuration to prevent this issue. See the linked GHSA for details.