CSRF Vulnerability in Drupal 8.2.x by Drupal
CVE-2017-6379
7.5HIGH
Summary
In Drupal versions 8.2.x prior to 8.2.7, certain administrative pathways lacked adequate CSRF protections. This oversight could enable attackers to disable specific blocks on affected websites, leading to potential manipulation of site content. Mitigation measures could be compromised if attackers were privy to the corresponding block IDs, emphasizing the need for awareness and updated security practices.
Affected Version(s)
Drupal Core 8.2.x versions before 8.2.7
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved