Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-087
HistoryMay 30, 2012 - 12:00 a.m.

SA-CONTRIB-2012-087 - Comment Moderation - Cross Site Request Forgery

2012-05-3000:00:00
Drupal Security Team
www.drupal.org
8

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

This module enables you to moderate comments in an accelerated way, by providing a complete interface and all useful actions in a unique page.
The module doesn’t sufficiently protect the publish link URL, thus a Cross Site Request Forgery (CSRF) attack against an administrator could result in unintended publishing of comments.

CVE: CVE-2012-2716

Versions affected

  • Comment Moderation 6.x-1.x versions prior to 6.x-1.1.

Drupal core is not affected. If you do not use the contributed Comment Moderation module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Comment Moderation project page.

Reported by

Fixed by

Coordinated by

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2012-087