CSRF Vulnerability in CiviCRM Private Report Module for Drupal
CVE-2015-4391
Currently unrated
What is CVE-2015-4391?
The CiviCRM private report module for Drupal is susceptible to a cross-site request forgery (CSRF) vulnerability. This security flaw enables remote attackers to potentially hijack the authentication of users, allowing malicious requests that could lead to the deletion of sensitive reports. Users of versions 6.x-1.x prior to 6.x-1.2 and 7.x-1.x prior to 7.x-1.3 are especially at risk, as they may not have sufficient safeguards against unauthorized actions performed in the context of a user session.
