Vulnerability Bulletins |
SA-CORE-2013-003 - Drupal core - Multiple vulnerabilities |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2013-003Project: Drupal coreVersion: 6.x, 7.xDate: 2013-November-20Security risk: Highly criticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities were fixed in the supported Drupal core versions 6 and 7.Multiple vulnerabilities due to optimistic cross-site request forgery protection (Form API validation - Drupal 6 and 7)Drupals form API has built-in cross-site request forgery (CSRF) validation, and also allows any More info: https://www.drupal.org/SA-CORE-2013-003 |
|






