Show filters
572 Total Results
Displaying 21-30 of 572
Sort by:
Attacker Value
Unknown
CVE-2021-32632
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Pajbot is a Twitch chat bot. Pajbot versions prior to 1.52 are vulnerable to cross-site request forgery (CSRF). Hosters of the bot should upgrade to `v1.52` or `stable` to install the patch or, as a workaround, can add one modern dependency.
0
Attacker Value
Unknown
CVE-2021-25931
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection at `/opennms/admin/userGroupView/users/updateUser`. This flaw allows assigning `ROLE_ADMIN` security role to a normal user. Using this flaw, an attacker can trick the admin user to assign administrator privileges to a normal user by enticing him to click upon an attacker-controlled website.
0
Attacker Value
Unknown
CVE-2021-25930
Disclosure Date: May 20, 2021 (last updated February 22, 2025)
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection, and since there is no validation of an existing user name while renaming a user. As a result, privileges of the renamed user are being overwritten by the old user and the old user is being deleted from the user list.
0
Attacker Value
Unknown
CVE-2021-29624
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 have a "double submit" mechanism using cookies with an application deployed across multiple subdomains, e.g. "heroku"-style platform as a service. Version 3.1.0 of the fastify-csrf fixes it. the vulnerability. The user of the module would need to supply a `userInfo` when generating the CSRF token to fully implement the protection on their end. This is needed only for applications hosted on different subdomains.
0
Attacker Value
Unknown
CVE-2020-24740
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
0
Attacker Value
Unknown
CVE-2020-18198
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."
0
Attacker Value
Unknown
CVE-2020-18195
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."
0
Attacker Value
Unknown
CVE-2021-24324
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to the lack of sanitisation and escaping in some fields, it could also lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-32403
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.
0
Attacker Value
Unknown
CVE-2021-32402
Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules.
0