#VU6109 Cross-site request forgery in Drupal - CVE-2017-6379
Published: March 17, 2017
Drupal
Drupal
Description
The vulnerability allows a remote attacker to perform CSRF attacks.
The vulnerability exists due to certain administrative forms do not have protection against CSRF attacks. A remote attacker can create a specially crafted website, trick the logged-in administrator to visit it and disable some blocks on affected website.
Successful exploitation of the vulnerability requires knowledge of block identifier.