Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2015-094
HistoryApr 08, 2015 - 12:00 a.m.

CiviCRM private report - Moderately Critical - Cross Site Request Forgery (CSRF) - SA-CONTRIB-2015-094

2015-04-0800:00:00
Drupal Security Team
www.drupal.org
7

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

CiviCRM private report module enables users to create their own private copies of CiviCRM reports, which they can modify and save to meet their needs without requiring the “Administer reports” permission.

The module doesn’t sufficiently protect some links against CSRF. A malicious user can cause another user to delete reports by getting their browser to make a request to a specially-crafted URL.

CVE identifier(s) issued

  • CVE-2015-4391

Versions affected

  • CiviCRM private report 6.x-1.x versions prior to 6.x-1.2.
  • CiviCRM private report 7.x-1.x versions prior to 7.x-1.3.

Drupal core is not affected. If you do not use the contributed CiviCRM private report module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the CiviCRM private report module for Drupal 6.x, upgrade to CiviCRM private report 6.x-1.2
  • If you use the CiviCRM private report module for Drupal 7.x, upgrade to CiviCRM private report 7.x-1.3

Also see the CiviCRM private report project page.

Reported by

Fixed by

Coordinated by

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.967 High

EPSS

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2015-094