Filtered by CWE-352
Total 7170 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-9270 1 Icehrm 1 Icehrm 2024-11-21 8.8 High
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
CVE-2020-9267 1 Soplanning 1 Soplanning 2024-11-21 6.5 Medium
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
CVE-2020-9266 1 Soplanning 1 Soplanning 2024-11-21 6.5 Medium
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
CVE-2020-9042 1 Couchbase 1 Couchbase Server 2024-11-21 8.8 High
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request.
CVE-2020-9018 1 Litecart 1 Litecart 2024-11-21 5.3 Medium
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
CVE-2020-8985 1 Zend 1 Zendto 2024-11-21 8.8 High
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
CVE-2020-8976 1 Zigor 2 Zgr Tps200 Ng, Zgr Tps200 Ng Firmware 2024-11-21 9.6 Critical
The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious request.
CVE-2020-8830 1 Commscope 2 Ruckus Zoneflex R500, Ruckus Zoneflex R500 Firmware 2024-11-21 8.8 High
CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.
CVE-2020-8829 1 Intelbras 2 Cip 92200, Cip 92200 Firmware 2024-11-21 8.8 High
CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.
CVE-2020-8658 1 Bestwebsoft 1 Htaccess 2024-11-21 8.8 High
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.
CVE-2020-8615 1 Themeum 1 Tutor Lms 2024-11-21 6.5 Medium
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
CVE-2020-8505 1 Arox 1 School Management Software Php\/mysql 2024-11-21 6.5 Medium
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
CVE-2020-8504 1 Arox 1 School Management Software Php\/mysql 2024-11-21 6.5 Medium
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.
CVE-2020-8465 1 Trendmicro 1 Interscan Web Security Virtual Appliance 2024-11-21 9.8 Critical
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.
CVE-2020-8461 1 Trendmicro 1 Interscan Web Security Virtual Appliance 2024-11-21 8.8 High
A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.
CVE-2020-8425 1 Cups Easy \(purchase \& Inventory\) Project 1 Cups Easy \(purchase \& Inventory\) 2024-11-21 6.5 Medium
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
CVE-2020-8424 1 Cups Easy Project 1 Cups Easy 2024-11-21 8.8 High
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
CVE-2020-8420 1 Joomla 1 Joomla\! 2024-11-21 8.8 High
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
CVE-2020-8419 1 Joomla 1 Joomla\! 2024-11-21 8.8 High
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
CVE-2020-8417 1 Codesnippets 1 Code Snippets 2024-11-21 8.8 High
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.