Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Services模块跨站请求伪造漏洞
Vulnerability Description
Service for Drupal是Drupal的一个标准化的API。提供创建服务或者方法的集合,以及通过不同的方式来调用远程站点的方法等功能。 Drupal的Services模块中存在跨站请求伪造漏洞。远程攻击者可利用该漏洞执行某些未授权操作,并获得对受影响程序的访问权限。以下版本中存在漏洞:Services 6.x-3.x版本,Services 7.x-3.4之前的7.x-3.x版本。
CVSS Information
N/A
Vulnerability Type
N/A