Show filters
1,404 Total Results
Displaying 51-60 of 1,404
Sort by:
Attacker Value
Unknown

CVE-2022-2001

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the dxss_admin_page() function found in the ~/dx-share-selection.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-1912

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-22359

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.
Attacker Value
Unknown

CVE-2022-32320

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file.
Attacker Value
Unknown

CVE-2022-2146

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting
Attacker Value
Unknown

CVE-2022-2144

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack
Attacker Value
Unknown

CVE-2022-1672

Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
Attacker Value
Unknown

CVE-2021-38868

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.
Attacker Value
Unknown

CVE-2022-34367

Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, leading to processing of unintended server operations.
Attacker Value
Unknown

CVE-2022-35228

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.