Drupal MultiSafepay Integration Module Cross Site Request Forgery Vulnerability
BID:41451
Info
Drupal MultiSafepay Integration Module Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 41451 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2010 12:00AM |
| Updated: | Jul 07 2010 12:00AM |
| Credit: | Peter Wolanin of the Drupal security team |
| Vulnerable: |
Drupal uc_multisafepay 6.x-1.0 |
| Not Vulnerable: |
Drupal uc_multisafepay 6.x-1.1 |
Discussion
Drupal MultiSafepay Integration Module Cross Site Request Forgery Vulnerability
The MultiSafepay Integration module 'uc_multisafepay' for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to modify the status of orders. Other attacks may also be possible.
Versions prior to uc_multisafepay 6.x-1.1 are vulnerable.
The MultiSafepay Integration module 'uc_multisafepay' for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to modify the status of orders. Other attacks may also be possible.
Versions prior to uc_multisafepay 6.x-1.1 are vulnerable.
Exploit / POC
Drupal MultiSafepay Integration Module Cross Site Request Forgery Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Drupal MultiSafepay Integration Module Cross Site Request Forgery Vulnerability
Solution:
An update is available. Please see the references for more details.
Drupal uc_multisafepay 6.x-1.0
Solution:
An update is available. Please see the references for more details.
Drupal uc_multisafepay 6.x-1.0
-
Drupal uc_multisafepay-6.x-1.1.tar.gz
http://ftp.drupal.org/files/projects/uc_multisafepay-6.x-1.1.tar.gz
References
Drupal MultiSafepay Integration Module Cross Site Request Forgery Vulnerability
References:
References: