PT-2013-1516 · Drupal · Drupal

Publicado

2013-10-28

·

Atualizado

2014-03-08

·

CVE-2012-0826

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 6.x before 6.23 Drupal versions 7.x before 7.11
Description A cross-site request forgery (CSRF) issue exists in the Aggregator module, allowing remote attackers to hijack the authentication of victims for requests that update feeds. This could potentially cause a denial of service due to rate limit, resulting in the loss of updates.
Recommendations For Drupal 6.x, update to version 6.23 or later. For Drupal 7.x, update to version 7.11 or later.

Correção

DoS

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0826
DSA-2776-1

Produtos afetados

Drupal