Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://drupal.org/node/2012366 | vendor advisory |
http://secunia.com/advisories/53649 | third party advisory vendor advisory |
http://secunia.com/advisories/53661 | third party advisory vendor advisory |
https://drupal.org/node/2012982 | vendor advisory |
http://osvdb.org/93980 | vdb entry |
http://www.securityfocus.com/bid/60356 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/84791 | vdb entry |
http://seclists.org/fulldisclosure/2013/Jun/23 | mailing list |