Show filters
447 Total Results
Displaying 11-20 of 447
Sort by:
Attacker Value
Unknown
CVE-2020-4827
Disclosure Date: February 02, 2021 (last updated February 22, 2025)
IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189841.
0
Attacker Value
Unknown
CVE-2020-4826
Disclosure Date: February 02, 2021 (last updated February 22, 2025)
IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 189840.
0
Attacker Value
Unknown
CVE-2020-24271
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***.
0
Attacker Value
Unknown
CVE-2020-29004
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.
0
Attacker Value
Unknown
CVE-2020-28403
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.
0
Attacker Value
Unknown
CVE-2020-13569
Disclosure Date: January 28, 2021 (last updated February 22, 2025)
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-20621
Disclosure Date: January 28, 2021 (last updated February 22, 2025)
Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2020-35239
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.
0
Attacker Value
Unknown
CVE-2021-21275
Disclosure Date: January 25, 2021 (last updated February 22, 2025)
The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of MediaWiki edit tokens.
0
Attacker Value
Unknown
CVE-2020-28452
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-session:core_2.11; the package com.softwaremill.akka-http-session:core_2.13 from 0 and before 0.6.1. CSRF protection can be bypassed by forging a request that contains the same value for both the X-XSRF-TOKEN header and the XSRF-TOKEN cookie value, as the check in randomTokenCsrfProtection only checks that the two values are equal and non-empty.
0