PT-2010-5522 · Drupal · Drupal
Josh Bressers
·
Publicado
2010-12-23
·
Atualizado
2010-12-27
·
CVE-2010-4519
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Drupal Views module versions 5.x before 5.x-1.8
Drupal Views module versions 6.x before 6.x-2.11
Description
The issue affects the Views UI implementation in the Views module for Drupal, where multiple cross-site request forgery (CSRF) vulnerabilities are present. These vulnerabilities allow remote attackers to hijack the authentication of administrators for specific requests, including enabling or disabling all Views.
Recommendations
For Drupal Views module version 5.x, update to version 5.x-1.8 or later.
For Drupal Views module version 6.x, update to version 6.x-2.11 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal