Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2013-018
HistoryFeb 20, 2013 - 12:00 a.m.

SA-CONTRIB-2013-018 - Taxonomy Manager - Cross Site Request Forgery (CSRF)

2013-02-2000:00:00
Drupal Security Team
www.drupal.org
4

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

60.3%

The Taxonomy Manager provides an advanced interface for administrating taxonomy vocabularies.

The module doesn’t sufficiently verify POST requests thereby exposing a Cross Site Request Forgery vulnerability.

This vulnerability is mitigated by the fact that an attacker must trick a user with ‘administer taxonomy’ permissions onto a prepared page with a site-specific malicious HTML form submission.

CVE identifier(s) issued

  • CVE-2013-0320

Versions affected

  • Taxonomy Manager 6.x-2.x versions prior to 6.x-2.2.
  • Taxonomy Manager 7.x-1.x versions prior to 7.x-1.0-rc1.

Drupal core is not affected. If you do not use the contributed Taxonomy Manager module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Taxonomy Manager module for Drupal 6.x, upgrade to Taxonomy Manager 6.x-2.3
  • If you use the Taxonomy Manager module for Drupal 7.x, upgrade to Taxonomy Manager 7.x-1.0-rc2

Also see the Taxonomy Manager project page.

Reported by

Fixed by

Coordinated by

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

60.3%

Related for DRUPAL-SA-CONTRIB-2013-018