PT-2008-2197 · Drupal · Userpoints Module

Greg Knaddison

+1

·

Publicado

2008-02-05

·

Atualizado

2011-03-08

·

CVE-2008-0571

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Userpoints module for Drupal versions 4.7.x before 4.7.x-2.3 Userpoints module for Drupal versions 5.x-2 before 5.x-2.16 Userpoints module for Drupal versions 5.x-3 before 5.x-3.3
Description The issue concerns the point moderation form in the Userpoints module for Drupal, which does not adhere to Drupal's Forms API submission model. This allows remote attackers to conduct cross-site request forgery (CSRF) attacks, enabling them to manipulate points.
Recommendations For Userpoints module for Drupal version 4.7.x, update to version 4.7.x-2.3 or later. For Userpoints module for Drupal version 5.x-2, update to version 5.x-2.16 or later. For Userpoints module for Drupal version 5.x-3, update to version 5.x-3.3 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0571

Produtos afetados

Userpoints Module