Show filters
759 Total Results
Displaying 31-40 of 759
Sort by:
Attacker Value
Unknown

CVE-2021-29837

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204913.
Attacker Value
Unknown

CVE-2020-21386

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.
Attacker Value
Unknown

CVE-2021-41295

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious web page and execute CRUD commands (GET, POST, PUT, DELETE) to perform arbitrary operations in the system.
0
Attacker Value
Unknown

CVE-2021-41764

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.
Attacker Value
Unknown

CVE-2020-20693

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.
Attacker Value
Unknown

CVE-2021-34636

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.5.7.
0
Attacker Value
Unknown

CVE-2021-40108

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.
Attacker Value
Unknown

CVE-2021-3819

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2021-31604

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
Attacker Value
Unknown

CVE-2020-20514

Disclosure Date: September 24, 2021 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.