PT-2009-1644 · Drupal · Localization Client+2
Publicado
2009-02-19
·
Atualizado
2017-08-17
·
CVE-2008-6169
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Localization client versions 5.x through 5.x-1.1
Localization client versions 6.x through 6.x-1.6
Localization server versions 5.x through 5.x-1.0-alpha5
Localization server versions 6.x through 6.x-alpha2
Description
A cross-site request forgery (CSRF) issue exists in the Localization client and server modules for Drupal. This allows remote attackers to perform unauthorized actions as administrators via vectors related to the local translation submission interface.
Recommendations
For Localization client versions 5.x through 5.x-1.1, update to version 5.x-1.1 or later.
For Localization client versions 6.x through 6.x-1.6, update to version 6.x-1.6 or later.
For Localization server versions 5.x through 5.x-1.0-alpha5, update to version 5.x-1.0-alpha5 or later.
For Localization server versions 6.x through 6.x-alpha2, update to version 6.x-alpha2 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal
Localization Client
Localization Server