5.1 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:H/Au:N/C:P/I:P/A:P
0.967 High
EPSS
Percentile
99.7%
The eXtensible Catalog Drupal Toolkit is a set of Drupal modules to harvest records of the XC Schema format from a Metadata Services Toolkit (MST).
The XC NCIP Provider module doesn’t sufficiently protect some URLs against CSRF. A malicious user can cause a user with “administer ncip providers” permission to alter NCIP providers by getting their browser to make a request to a specially-crafted URL.
This vulnerability is mitigated by the fact that only sites that have the XC NCIP Provider module enabled are affected.
Drupal core is not affected. If you do not use the contributed The eXtensible Catalog (XC) Drupal Toolkit module, there is nothing you need to do.
Install the latest version:
Also see the The eXtensible Catalog (XC) Drupal Toolkit project page.