Cross-site request forgery in Drupal - CVE-2015-6660

 

Cross-site request forgery in Drupal - CVE-2015-6660

Published: September 14, 2016


Vulnerability identifier: #VU429
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-6660
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform cross-site request forgery.
The weakness is caused by unsufficient input checking. Attackers can upload temporary malicious files under the account of another user.
Successful exploitation of this vulnerability may result in CSRF conducting.

Affected software

Drupal
Fedora
drupal6
drupal7

How to mitigate CVE-2015-6660


drupal6 - addressed in versions 6.37-1.el5, 6.37-1.el6, 6.37-1.fc21, 6.37-1.fc22, 6.37-1.fc23
drupal7 - addressed in versions 7.39-1.el5, 7.39-1.el6, 7.39-1.el7, 7.39-1.fc21, 7.39-1.fc22, 7.39-1.fc23

External References

Related Security Bulletins