Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8mj-2m92-pmqv

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

EPSS

Процентиль: 64%
0.00475
Низкий

Дефекты

CWE-352

Связанные уязвимости

ubuntu
больше 17 лет назад

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

nvd
больше 17 лет назад

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

debian
больше 17 лет назад

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection a ...

EPSS

Процентиль: 64%
0.00475
Низкий

Дефекты

CWE-352