CSRF Vulnerability in CiviCRM Private Report Module for Drupal
CVE-2015-4391

Currently unrated

Key Information:

Vendor

Civicrm

Vendor
CVE Published:
15 June 2015

What is CVE-2015-4391?

The CiviCRM private report module for Drupal is susceptible to a cross-site request forgery (CSRF) vulnerability. This security flaw enables remote attackers to potentially hijack the authentication of users, allowing malicious requests that could lead to the deletion of sensitive reports. Users of versions 6.x-1.x prior to 6.x-1.2 and 7.x-1.x prior to 7.x-1.3 are especially at risk, as they may not have sufficient safeguards against unauthorized actions performed in the context of a user session.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.