PT-2013-1516 · Drupal · Drupal

Published

2013-10-28

·

Updated

2014-03-08

·

CVE-2012-0826

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 6.x before 6.23 Drupal versions 7.x before 7.11
Description A cross-site request forgery (CSRF) issue exists in the Aggregator module, allowing remote attackers to hijack the authentication of victims for requests that update feeds. This could potentially cause a denial of service due to rate limit, resulting in the loss of updates.
Recommendations For Drupal 6.x, update to version 6.23 or later. For Drupal 7.x, update to version 7.11 or later.

Fix

DoS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-0826
DSA-2776-1

Affected Products

Drupal