6.8
CVE-2008-6169
- EPSS 0.21%
- Veröffentlicht 19.02.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drupal ≫ Localization Client Version <= 5.x-1.0
Drupal ≫ Localization Client Version <= 6.x-1.5
Drupal ≫ Localization Client Version5.x-1.xdev
Drupal ≫ Localization Client Version6.x-1.0
Drupal ≫ Localization Client Version6.x-1.1
Drupal ≫ Localization Client Version6.x-1.2
Drupal ≫ Localization Client Version6.x-1.3
Drupal ≫ Localization Client Version6.x-1.4
Drupal ≫ Localization Client Version6.x-1.xdev
Drupal ≫ Localization Server Version <= 5.x-1.0alpha4
Drupal ≫ Localization Server Version <= 6.x-1.0alpha1
Drupal ≫ Localization Server Version5.x-1.0alpha1
Drupal ≫ Localization Server Version5.x-1.0alpha2
Drupal ≫ Localization Server Version5.x-1.0alpha3
Drupal ≫ Localization Server Version5.x-1.xdev
Drupal ≫ Localization Server Version6.x-1.xdev
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.397 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.