Lucene search

K
cve[email protected]CVE-2015-3350
HistoryApr 21, 2015 - 4:59 p.m.

CVE-2015-3350

2015-04-2116:59:10
CWE-352
web.nvd.nist.gov
19
cve-2015-3350
cross-site request forgery
csrf
todo filter module
drupal
vulnerability
hijacking
authentication
remote attackers

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.7%

Cross-site request forgery (CSRF) vulnerability in the Todo Filter module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that toggle a task via unspecified vectors.

Affected configurations

NVD
Node
todo_filter_projecttodo_filterRange6.x-1.0drupal
OR
todo_filter_projecttodo_filterMatch7.x-1.0drupal
OR
todo_filter_projecttodo_filterMatch7.x-1.x-devdrupal

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.4 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

59.7%

Related for CVE-2015-3350