CSRF Vulnerability in Drupal 8.2.x by Drupal
CVE-2017-6379

7.5HIGH

Key Information:

Vendor
Drupal
Vendor
CVE Published:
16 March 2017

Summary

In Drupal versions 8.2.x prior to 8.2.7, certain administrative pathways lacked adequate CSRF protections. This oversight could enable attackers to disable specific blocks on affected websites, leading to potential manipulation of site content. Mitigation measures could be compromised if attackers were privy to the corresponding block IDs, emphasizing the need for awareness and updated security practices.

Affected Version(s)

Drupal Core 8.2.x versions before 8.2.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.