CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
EPSS
Percentile
99.7%
The Custom Sitemap module enables you to add custom sitemaps to a site.
The module doesn’t sufficiently protect some URLs against CSRF. A malicious user could trick an administrator into deleting sitemaps by getting their browser to make a request to a specially-crafted URL.
All versions of Custom Sitemap module.
Drupal core is not affected. If you do not use the contributed Custom Sitemap module, there is nothing you need to do.
If you use the Custom Sitemap module you should uninstall it.
Also see the Custom Sitemap project page.
Not applicable.