Drupal Heartbeat Module Cross Site Request Forgery Vulnerability
BID:55422
Info
Drupal Heartbeat Module Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 55422 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2012 12:00AM |
| Updated: | Sep 05 2012 12:00AM |
| Credit: | Greg Knaddison of the Drupal Security Team |
| Vulnerable: |
Drupal Heartbeat 6.x-4.9 Drupal Heartbeat 6.x-4.8 |
| Not Vulnerable: | |
Discussion
Drupal Heartbeat Module Cross Site Request Forgery Vulnerability
The Heartbeat module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
The following versions are vulnerable:
Heartbeat 6.x-4.x versions prior to 6.x-4.11
Heartbeat 7.x-1.x versions prior to 7.x-1.0
The Heartbeat module for Drupal is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
The following versions are vulnerable:
Heartbeat 6.x-4.x versions prior to 6.x-4.11
Heartbeat 7.x-1.x versions prior to 7.x-1.0
Exploit / POC
Drupal Heartbeat Module Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious URI.