CVE-2015-4390
15.06.2015, 14:59
Multiple cross-site request forgery (CSRF) vulnerabilities in the User Import module 6.x-4.x before 6.x-4.4 and 7.x-2.x before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) continue or (2) delete an ongoing import via unspecified vectors.
Vendor | Product | Version |
---|---|---|
user_import_project | user_import | 6.x-4.0:x |
user_import_project | user_import | 6.x-4.1:x |
user_import_project | user_import | 6.x-4.2:x |
user_import_project | user_import | 6.x-4.3:x |
user_import_project | user_import | 6.x-4.x:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References