6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
0.967 High
EPSS
Percentile
99.7%
This module enables you to moderate comments in an accelerated way, by providing a complete interface and all useful actions in a unique page.
The module doesn’t sufficiently protect the publish link URL, thus a Cross Site Request Forgery (CSRF) attack against an administrator could result in unintended publishing of comments.
CVE: CVE-2012-2716
Drupal core is not affected. If you do not use the contributed Comment Moderation module, there is nothing you need to do.
Install the latest version:
Also see the Comment Moderation project page.
drupal.org/contact
drupal.org/node/1538768
drupal.org/project/comment_moderation
drupal.org/security-team
drupal.org/security-team/risk-levels
drupal.org/security/secure-configuration
drupal.org/user/457434
drupal.org/user/49385
drupal.org/user/96647
drupal.org/writing-secure-code
security.drupal.org/team-members