PT-2009-1644 · Drupal · Localization Client+2

Publicado

2009-02-19

·

Atualizado

2017-08-17

·

CVE-2008-6169

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Localization client versions 5.x through 5.x-1.1 Localization client versions 6.x through 6.x-1.6 Localization server versions 5.x through 5.x-1.0-alpha5 Localization server versions 6.x through 6.x-alpha2
Description A cross-site request forgery (CSRF) issue exists in the Localization client and server modules for Drupal. This allows remote attackers to perform unauthorized actions as administrators via vectors related to the local translation submission interface.
Recommendations For Localization client versions 5.x through 5.x-1.1, update to version 5.x-1.1 or later. For Localization client versions 6.x through 6.x-1.6, update to version 6.x-1.6 or later. For Localization server versions 5.x through 5.x-1.0-alpha5, update to version 5.x-1.0-alpha5 or later. For Localization server versions 6.x through 6.x-alpha2, update to version 6.x-alpha2 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6169

Produtos afetados

Drupal
Localization Client
Localization Server