Show filters
1,404 Total Results
Displaying 51-60 of 1,404
Sort by:
Attacker Value
Unknown
CVE-2022-2001
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the dxss_admin_page() function found in the ~/dx-share-selection.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-1912
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-22359
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 220652.
0
Attacker Value
Unknown
CVE-2022-32320
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file.
0
Attacker Value
Unknown
CVE-2022-2146
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2022-2144
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-1672
Disclosure Date: July 17, 2022 (last updated February 24, 2025)
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
0
Attacker Value
Unknown
CVE-2021-38868
Disclosure Date: July 15, 2022 (last updated February 24, 2025)
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.
0
Attacker Value
Unknown
CVE-2022-34367
Disclosure Date: July 14, 2022 (last updated February 24, 2025)
Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, leading to processing of unintended server operations.
0
Attacker Value
Unknown
CVE-2022-35228
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.
0