PT-2007-6614 · Drupal · Drupal

Publicado

2007-10-19

·

Atualizado

2021-04-19

·

CVE-2007-5594

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions prior to 5.3
Description The issue allows remote attackers to delete users via a cross-site request forgery (CSRF) attack because it does not apply its Drupal Forms API protection against the user deletion form.
Recommendations For versions prior to 5.3, update to version 5.3 or later to resolve the issue.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5594

Produtos afetados

Drupal