Show filters
1,008 Total Results
Displaying 21-30 of 1,008
Sort by:
Attacker Value
Unknown
CVE-2021-22724
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)
0
Attacker Value
Unknown
CVE-2021-44122
Disclosure Date: January 26, 2022 (last updated February 23, 2025)
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is also possible to combine XSS vulnerabilities in SPIP 4.0.0 to exploit it. The vulnerability allows an authenticated attacker to execute malicious code without the knowledge of the user on the website (CSRF).
0
Attacker Value
Unknown
CVE-2022-0335
Disclosure Date: January 25, 2022 (last updated February 23, 2025)
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.
0
Attacker Value
Unknown
CVE-2022-0269
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
0
Attacker Value
Unknown
CVE-2021-25073
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack
0
Attacker Value
Unknown
CVE-2021-25013
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
0
Attacker Value
Unknown
CVE-2021-24989
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog
0
Attacker Value
Unknown
CVE-2021-24968
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions
0
Attacker Value
Unknown
CVE-2021-24936
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2021-24696
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
0