CVE-2008-6532: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupalto a version that resolves this vulnerability.Fixed in 5.13 - Upgrade
Upgrade
Drupalto a version that resolves this vulnerability.Fixed in 6.7
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6532?
CVE-2008-6532 is considered a critical vulnerability due to its potential for exploitation through cross-site request forgery.
How do I fix CVE-2008-6532?
To fix CVE-2008-6532, update your Drupal installation to version 5.13 or 6.7 or later.
What versions of Drupal are affected by CVE-2008-6532?
CVE-2008-6532 affects Drupal versions 5.x before 5.13 and 6.x before 6.7.
What type of attack does CVE-2008-6532 involve?
CVE-2008-6532 involves cross-site request forgery (CSRF) that allows attackers to perform unauthorized actions.
Can CVE-2008-6532 affect system administrators?
Yes, CVE-2008-6532 can allow remote attackers to perform unauthorized actions as the superuser, potentially compromising the site.