Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal 8.2.7之前的8.2.x版本中存在跨站请求伪造漏洞,该漏洞源于程序没有对管理路径使用CSRF令牌保护。远程攻击者可利用该漏洞执行未授权的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Drupal Core | 8.2.x versions before 8.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-6377 | Drupal 安全漏洞 | |
| CVE-2017-6381 | Drupal 安全漏洞 |
No comments yet