Show filters
576 Total Results
Displaying 1-10 of 576
Sort by:
Attacker Value
Moderate
CVE-2020-35687
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
3
Attacker Value
Very Low
CVE-2020-9266
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
0
Attacker Value
Unknown
CVE-2020-13663
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.
0
Attacker Value
Unknown
CVE-2021-34547
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.
0
Attacker Value
Unknown
CVE-2021-31659
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information is placed in the URL, without any additional token authentication information. A malicious link opened by the switch administrator may cause the password of the switch to be modified and the configuration file to be tampered with.
0
Attacker Value
Unknown
CVE-2021-21665
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2021-32677
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable to a Cross-Site Request Forgery (CSRF) attack. In versions lower than 0.65.2, FastAPI would try to read the request payload as JSON even if the content-type header sent was not set to application/json or a compatible JSON media type (e.g. application/geo+json). A request with a content type of text/plain containing JSON data would be accepted and the JSON data would be extracted. Requests with content type text/plain are exempt from CORS preflights, for being considered Simple requests. The browser will execute them right away including cookies, and the text content could be a JSON string that would be parsed and accepted by the FastAPI application. This is fixed in FastAPI 0.65.2. The request data is now parsed as JSON only if the conten…
0
Attacker Value
Unknown
CVE-2021-29995
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.
0
Attacker Value
Unknown
CVE-2021-26474
Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
0
Attacker Value
Unknown
CVE-2020-26516
Disclosure Date: June 08, 2021 (last updated February 22, 2025)
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.
0