UBUNTU-CVE-2015-6660
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-6660
Summary:
Details: The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."
References: https://ubuntu.com/security/CVE-2015-6660, https://www.drupal.org/SA-CORE-2015-003, https://www.cve.org/CVERecord?id=CVE-2015-6660
Affected packages
Package
Name: drupal7
Purl: pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
7.23-1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
