CVE Database
/

CVE-2017-6379

Back to search

CVE-2017-6379

Published: Mar 16, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.

VendorProductVersions

Drupal

Drupal Core

affected
8.2.x versions before 8.2.7

References

1038058
vdb-entry
x_refsource_SECTRACK
96919
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now