Vulnerabilities (CVE)

Filtered by CWE-352
Total 6081 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7666 1 Apache 1 Openmeetings 2024-11-21 6.8 MEDIUM 8.8 HIGH
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
CVE-2017-7662 1 Apache 1 Cxf Fediz 2024-11-21 6.8 MEDIUM 8.8 HIGH
Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc. A CSRF (Cross Style Request Forgery) style vulnerability has been found in this web application in Apache CXF Fediz prior to 1.4.0 and 1.3.2, meaning that a malicious web application could create new clients, or reset secrets, etc, after the admin user has logged on to the client registration service and the session is still active.
CVE-2017-7661 1 Apache 1 Cxf Fediz 2024-11-21 6.8 MEDIUM 8.8 HIGH
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prior to 1.4.0, 1.3.2 and 1.2.4.
CVE-2017-7641 1 Qnap 2 Media Streaming Add-on, Qts 2024-11-21 6.8 MEDIUM 8.8 HIGH
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
CVE-2017-7635 1 Qnap 1 Nas Proxy Server 2024-11-21 6.8 MEDIUM 8.8 HIGH
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
CVE-2017-7620 1 Mantisbt 1 Mantisbt 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI.
CVE-2017-7571 1 Ladybirdweb 1 Faveo Helpdesk 2024-11-21 6.0 MEDIUM 8.0 HIGH
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
CVE-2017-7557 1 Powerdns 1 Dnsdist 2024-11-21 6.8 MEDIUM 8.8 HIGH
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
CVE-2017-7556 1 Hawt 1 Hawtio 2024-11-21 6.8 MEDIUM 8.8 HIGH
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.
CVE-2017-7491 1 Moodle 1 Moodle 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
CVE-2017-7447 1 Helpdezk 1 Helpdezk 2024-11-21 6.8 MEDIUM 8.8 HIGH
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
CVE-2017-7446 1 Helpdezk 1 Helpdezk 2024-11-21 6.8 MEDIUM 8.8 HIGH
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
CVE-2017-7431 2 Netiq, Novell 2 Imanager, Imanager 2024-11-21 6.8 MEDIUM 8.8 HIGH
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
CVE-2017-7423 1 Microfocus 2 Enterprise Developer, Enterprise Server 2024-11-21 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to forge requests, if this component is configured. This includes creating new privileged credentials, resulting in privilege elevation (CWE-275). Note esfadmingui is not enabled by default.
CVE-2017-7404 1 Dlink 1 Dir-615 2024-11-21 6.8 MEDIUM 8.8 HIGH
On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send requests to the victim's Router without knowing the credentials (CSRF). An attacker can host a page that sends a POST request to Form2File.htm that tries to upload Firmware to victim's Router. This causes the router to reboot/crash resulting in Denial of Service. An attacker may succeed in uploading malicious Firmware.
CVE-2017-7398 2 D-link, Dlink 2 Dir-615 Firmware, Dir-615 2024-11-21 6.8 MEDIUM 8.8 HIGH
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.
CVE-2017-7178 2 Debian, Deluge-torrent 2 Debian Linux, Deluge 2024-11-21 6.8 MEDIUM 8.8 HIGH
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.
CVE-2017-6918 1 Bigtreecms 1 Bigtree Cms 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
CVE-2017-6917 1 Bigtreecms 1 Bigtree Cms 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page. The Colophon can be changed.
CVE-2017-6916 1 Bigtreecms 1 Bigtree Cms 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.