Show filters
404 Total Results
Displaying 1-10 of 404
Sort by:
Attacker Value
Very Low

CVE-2020-9266

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
Attacker Value
Unknown

CVE-2018-16795

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.
Attacker Value
Unknown

CVE-2020-35778

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.
Attacker Value
Unknown

CVE-2020-35773

Disclosure Date: December 29, 2020 (last updated February 22, 2025)
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
Attacker Value
Unknown

CVE-2020-26033

Disclosure Date: December 28, 2020 (last updated February 22, 2025)
An issue was discovered in Zammad before 3.4.1. The Tag and Link REST API endpoints (for add and delete) lack a CSRF token check.
Attacker Value
Unknown

CVE-2020-35347

Disclosure Date: December 26, 2020 (last updated February 22, 2025)
CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.
Attacker Value
Unknown

CVE-2020-26766

Disclosure Date: December 26, 2020 (last updated February 22, 2025)
A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.
Attacker Value
Unknown

CVE-2020-35677

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resulting in Stored XSS. The caveat here is that an attacker would need administrative privileges in order to create the payload. One might think this completely mitigates the privilege-escalation impact as there is only one high-privileged role. However, it was discovered that the endpoint responsible for creating the group lacks CSRF protection.
Attacker Value
Unknown

CVE-2020-35269

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
Attacker Value
Unknown

CVE-2020-35626

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.