CVE-2009-4066: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4066?
CVE-2009-4066 has a medium severity level due to its potential for CSRF attacks against user accounts.
How do I fix CVE-2009-4066?
To fix CVE-2009-4066, update the PHPList Integration module to versions 5.x-1.2 or 6.x-1.1 or later.
Which versions are affected by CVE-2009-4066?
CVE-2009-4066 affects PHPList Integration module versions 5.x-1.0, 5.x-1.1, and 6.x-1.0.
What type of vulnerability is CVE-2009-4066?
CVE-2009-4066 is a cross-site request forgery (CSRF) vulnerability that allows attackers to hijack user sessions.
What can an attacker do with CVE-2009-4066?
An attacker can use CVE-2009-4066 to hijack the authentication of users via subscription or unsubscription actions.