CVE-2007-4063: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4063?
The severity of CVE-2007-4063 is classified as critical due to the potential for remote attackers to exploit multiple CSRF vulnerabilities.
How do I fix CVE-2007-4063?
To fix CVE-2007-4063, upgrade your Drupal installation to version 5.2 or later.
What platforms are affected by CVE-2007-4063?
CVE-2007-4063 affects Drupal versions 5.0, 5.1, and 5.1_rev1.1.
What types of attacks are possible with CVE-2007-4063?
With CVE-2007-4063, attackers can perform actions like deleting comments and content revisions or disabling menu items as privileged users.
Is CVE-2007-4063 a common vulnerability in Drupal?
Yes, CVE-2007-4063 is a known vulnerability that affected earlier versions of Drupal, particularly those before 5.2.