User Queue Module For Drupal Delete User Cross Site Request Forgery Vulnerability
BID:40284
Info
User Queue Module For Drupal Delete User Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 40284 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2010 12:00AM |
| Updated: | May 19 2010 12:00AM |
| Credit: | George Gongadze |
| Vulnerable: |
Drupal User Queue 6.x-1.0 |
| Not Vulnerable: |
Drupal User Queue 6.x-1.1 |
Discussion
User Queue Module For Drupal Delete User Cross Site Request Forgery Vulnerability
The User Queue module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
Versions prior to User Queue 6.x-1.1 are vulnerable.
The User Queue module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
Versions prior to User Queue 6.x-1.1 are vulnerable.
Exploit / POC
User Queue Module For Drupal Delete User Cross Site Request Forgery Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
User Queue Module For Drupal Delete User Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references for more information.
Drupal User Queue 6.x-1.0
Solution:
Updates are available. Please see the references for more information.
Drupal User Queue 6.x-1.0
-
Drupal userqueue-6.x-1.1.tar.gz
http://ftp.drupal.org/files/projects/userqueue-6.x-1.1.tar.gz
References
User Queue Module For Drupal Delete User Cross Site Request Forgery Vulnerability
References:
References: