Vulnerability Bulletins |
SA-2008-005 - Drupal core - Cross site request forgery |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-2008-005Project: Drupal coreVersion: 4.7.x, 5.xDate: 2008-January-10Security risk: Less criticalExploitable from: RemoteVulnerability: Cross site request forgeryDescriptionThe aggregator module fetches items from RSS feeds and makes them available on the site. The module provides an option to remove items from a particular feed. This has been implemented as a simple GET request and is therefore vulnerable to cross site request forgeries. For example: Should a privileged More info: https://www.drupal.org/node/208562 |
|






