CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
99.7%
The Contact Form Fields module enables you to create additional fields to site-wide contact form.
Some links were not properly protected from CSRF. A malicious user could cause an administrator to delete fields by getting the administrator’s browser to make a request to a specially-crafted URL while the administrator was logged in.
Drupal core is not affected. If you do not use the contributed Contact form fields module,
there is nothing you need to do.
Install the latest version:
Also see the Contact form fields project page.