First published: Mon Mar 02 2009(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack the authentication of administrators.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Comment Mail | =5.x-1.0-beta | |
Drupal Comment Mail | =5.x-1.x-dev | |
Drupal Comment Mail | =5.x-1.0 | |
Drupal Comment Mail | =5.x-0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6384 is considered a critical vulnerability due to the potential for remote attackers to hijack administrator sessions.
To fix CVE-2008-6384, update the Comment Mail module to version 5.x-1.1 or later.
CVE-2008-6384 can lead to unauthorized actions being performed as an administrator, compromising the security of the Drupal site.
Yes, CVE-2008-6384 affects Comment Mail versions 5.x before 5.x-1.1.
Administrators using affected versions of the Comment Mail module for Drupal are at risk due to CVE-2008-6384.