SB2016092117 - Cross-site request forgery in Drupal Drupal



SB2016092117 - Cross-site request forgery in Drupal Drupal

Published: September 21, 2016

Security Bulletin ID SB2016092117
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site request forgery (CVE-ID: N/A)

The vulnerability allows a remote user to perform cross-site request forgery attack.
The weakness is caused by improper access control. After tricking the victim into visiting specially crafted URL(s), attackers can change passwords, post PHP code or create new users.
Successful exploitation of the vulnerability enables a malicious user to conduct CSRF attack.

Remediation

Install update from vendor's website.