First published: Fri Jul 18 2008(Updated: )
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | >=6.0<6.3 | |
Drupal | >=5.0<5.8 | |
Fedora | =9 | |
Fedora | =8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3220 is classified as a medium severity vulnerability due to its potential impact on administrative actions on affected Drupal installations.
To fix CVE-2008-3220, update your Drupal installation to version 5.8 or later for Drupal 5.x, and to version 6.3 or later for Drupal 6.x.
CVE-2008-3220 affects Drupal versions prior to 5.8 and 6.3, as well as Fedora 8 and 9 if they are running these versions.
CVE-2008-3220 is a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unauthorized administrative actions.
Using Drupal 5.x or 6.x without applying the necessary updates puts your site at risk of being exploited through CVE-2008-3220.