Filtered by CWE-352
Total 8021 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-17996 1 Layerbb 1 Layerbb 2024-11-21 N/A
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.
CVE-2018-17986 1 Razorcms 1 Razorcms 2024-11-21 N/A
rars/user/data in razorCMS 3.4.8 allows CSRF for changing the password of an admin user.
CVE-2018-17869 1 Dasan 2 H660gw, H660gw Firmware 2024-11-21 N/A
DASAN H660GW devices do not implement any CSRF protection mechanism.
CVE-2018-17858 1 Joomla 1 Joomla\! 2024-11-21 N/A
An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.
CVE-2018-17826 1 Hisiphp 1 Hisiphp 2024-11-21 N/A
HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging app/common/model/AdminAnnex.php to add .php to the default list of allowable file-upload types (.jpg, .png, .gif, .jpeg, and .ico).
CVE-2018-17792 1 Altn 1 Mdaemon Webmail 2024-11-21 N/A
MDaemon Webmail (formerly WorldClient) has CSRF.
CVE-2018-17789 1 Prospecta 1 Master Data Online 2024-11-21 6.5 Medium
Prospecta Master Data Online (MDO) allows CSRF.
CVE-2018-17584 1 Wpfastestcache 1 Wp Fastest Cache 2024-11-21 N/A
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
CVE-2018-17429 1 Jtbc 1 Jtbc 2024-11-21 N/A
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.
CVE-2018-17389 1 Ranksol 1 Live Call Support 2024-11-21 N/A
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
CVE-2018-17387 1 Ranksol 1 Nimble Professional 2024-11-21 N/A
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
CVE-2018-17366 1 Mcms Project 1 Mcms 2024-11-21 N/A
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
CVE-2018-17168 1 Printeron 1 Printeron 2024-11-21 N/A
PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administrator, by following a link, can be tricked into making unwanted changes to a printer (Disable, Approve, etc).
CVE-2018-17104 1 Microweber 1 Microweber 2024-11-21 N/A
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
CVE-2018-17103 1 Get-simple 1 Getsimple Cms 2024-11-21 N/A
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter
CVE-2018-17102 1 Quickappscms 1 Quickapps Cms 2024-11-21 N/A
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI.
CVE-2018-17081 1 E107 1 E107 2024-11-21 N/A
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
CVE-2018-17070 1 Unlcms 1 Unlcms 2024-11-21 N/A
An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay.
CVE-2018-17069 1 Unlcms 1 Unlcms 2024-11-21 N/A
An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.
CVE-2018-17045 1 Cms Maelostore Project 1 Cms Maelostore 2024-11-21 N/A
An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via admin/modul/users/aksi_users.php?act=update.