Filtered by CWE-352
Total 8021 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-18799 1 School Attendance Monitoring System Project 1 School Attendance Monitoring System 2024-11-21 N/A
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
CVE-2018-18797 1 School Attendance Monitoring System Project 1 School Attendance Monitoring System 2024-11-21 N/A
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
CVE-2018-18794 1 School Event Management System Project 1 School Event Management System 2024-11-21 N/A
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
CVE-2018-18773 1 Control-webpanel 1 Webpanel 2024-11-21 N/A
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.
CVE-2018-18772 1 Control-webpanel 1 Webpanel 2024-11-21 N/A
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.
CVE-2018-18742 1 Sem-cms 1 Semcms 2024-11-21 N/A
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
CVE-2018-18735 1 Catfish-cms 1 Catfish Blog 2024-11-21 N/A
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
CVE-2018-18734 1 Catfish-cms 1 Catfish Cms 2024-11-21 N/A
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.
CVE-2018-18696 1 Microstrategy 1 Microstrategy 2024-11-21 N/A
main.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF attack has been provided (https://community.microstrategy.com/s/article/KB37643-New-security-feature-introduced-in-MicroStrategy-Web-9-0?language=en_US) and disagrees that this issue is a vulnerability. They also claim that MicroStrategy was never properly informed of this issue via normal support channels or their vulnerability reporting page on their website, so they were unable to evaluate the report or explain how this is something their customers view as a feature and not a security vulnerability
CVE-2018-18449 1 Phome 1 Empirecms 2024-11-21 N/A
EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339.
CVE-2018-18436 1 Jtbc 1 Jtbc Php 2024-11-21 8.8 High
JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.
CVE-2018-18432 1 Destoon 1 Destoon B2b 2024-11-21 N/A
An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.
CVE-2018-18422 1 Usualtool 1 Usualtoolcms 2024-11-21 N/A
UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.
CVE-2018-18420 1 Tribalsystems 1 Zenario 2024-11-21 N/A
Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI.
CVE-2018-18317 1 Dscms Project 1 Dscms 2024-11-21 N/A
DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.
CVE-2018-18316 1 Emlog 1 Emlog 2024-11-21 N/A
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
CVE-2018-18246 1 Icinga 1 Icinga Web 2 2024-11-21 N/A
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
CVE-2018-18215 1 Youke365 1 Youke 365 2024-11-21 N/A
In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.
CVE-2018-18201 1 Qibosoft 1 Qibosoft 2024-11-21 N/A
qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.
CVE-2018-18191 1 Finecms 1 Finecms 2024-11-21 N/A
Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the administrator's password.