PT-2008-2197 · Drupal · Userpoints Module
Greg Knaddison
+1
·
Publicado
2008-02-05
·
Atualizado
2011-03-08
·
CVE-2008-0571
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Userpoints module for Drupal versions 4.7.x before 4.7.x-2.3
Userpoints module for Drupal versions 5.x-2 before 5.x-2.16
Userpoints module for Drupal versions 5.x-3 before 5.x-3.3
Description
The issue concerns the point moderation form in the Userpoints module for Drupal, which does not adhere to Drupal's Forms API submission model. This allows remote attackers to conduct cross-site request forgery (CSRF) attacks, enabling them to manipulate points.
Recommendations
For Userpoints module for Drupal version 4.7.x, update to version 4.7.x-2.3 or later.
For Userpoints module for Drupal version 5.x-2, update to version 5.x-2.16 or later.
For Userpoints module for Drupal version 5.x-3, update to version 5.x-3.3 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Userpoints Module