PT-2010-5522 · Drupal · Drupal
Josh Bressers
·
Published
2010-12-23
·
Updated
2010-12-27
·
CVE-2010-4519
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Drupal Views module versions 5.x before 5.x-1.8
Drupal Views module versions 6.x before 6.x-2.11
Description
The issue affects the Views UI implementation in the Views module for Drupal, where multiple cross-site request forgery (CSRF) vulnerabilities are present. These vulnerabilities allow remote attackers to hijack the authentication of administrators for specific requests, including enabling or disabling all Views.
Recommendations
For Drupal Views module version 5.x, update to version 5.x-1.8 or later.
For Drupal Views module version 6.x, update to version 6.x-2.11 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal