Total
6085 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-14319 | 1 Redhat | 2 Amq Online, Enmasse | 2024-11-21 | 4.0 MEDIUM | 5.9 MEDIUM |
It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks are not instigated or bypassed. For example authorised users using an older browser with Adobe Flash are vulnerable when targeted by an attacker. This flaw affects all versions of AMQ-Online prior to 1.5.2 and Enmasse versions 0.31.0-rc1 up until but not including 0.32.2. | |||||
CVE-2020-14203 | 1 Ibi | 1 Webfocus Business Intelligence | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with CVE-2016-9044. | |||||
CVE-2020-14043 | 1 Codiad | 1 Codiad | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in components/market/controller.php. This might cause admins to make a vulnerable request without them knowing and result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors." | |||||
CVE-2020-14025 | 1 Ozeki | 1 Ozeki Ng Sms Gateway | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password. | |||||
CVE-2020-13868 | 1 Verbb | 1 Comments | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. | |||||
CVE-2020-13786 | 1 Dlink | 2 Dir-865l, Dir-865l Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF. | |||||
CVE-2020-13760 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. | |||||
CVE-2020-13674 | 1 Drupal | 1 Drupal | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is installed. Removing the "access in-place editing" permission from untrusted users will not fully mitigate the vulnerability. | |||||
CVE-2020-13663 | 1 Drupal | 1 Drupal | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities. | |||||
CVE-2020-13658 | 1 Lansweeper | 1 Lansweeper | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application. | |||||
CVE-2020-13643 | 1 Siteorigin | 1 Page Builder | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser. | |||||
CVE-2020-13642 | 1 Siteorigin | 1 Page Builder | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser. | |||||
CVE-2020-13641 | 1 Infolific | 1 Real-time Find And Replace | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser. | |||||
CVE-2020-13620 | 1 Fastweb | 2 Fastgate Gpon Fga2130fwb, Fastgate Gpon Fga2130fwb Firmware | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration. | |||||
CVE-2020-13569 | 1 Open-emr | 1 Openemr | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can send an HTTP request to trigger this vulnerability. | |||||
CVE-2020-13527 | 1 Lantronix | 4 Sgx, Sgx Firmware, Xport Edge and 1 more | 2024-11-21 | 3.5 LOW | 4.5 MEDIUM |
An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability. | |||||
CVE-2020-13460 | 1 Tufin | 1 Securetrack | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA. | |||||
CVE-2020-13458 | 1 Verbb | 1 Image Resizer | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action. | |||||
CVE-2020-13426 | 1 Bdtask | 1 Multi-scheduler | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known. | |||||
CVE-2020-13416 | 1 Aviatrix | 1 Controller | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets. |