SB2013120701 - Cross-site request forgery in Drupal Drupal
Published: December 7, 2013 Updated: September 15, 2016
Security Bulletin ID
SB2013120701
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site request forgery (CVE-ID: CVE-2013-6385)
The vulnerability allows a remote user to perform cross-site request forgery attack.The weakness exists due to improper functionality of form API validation preventing CSRF. The form carrying out unsafe operations will expose the system to cross-site request forgery attacks.
Successful expliation of the vulnerability allows attackers to conduct CSRF.
Remediation
Install update from vendor's website.