CVE-2010-1547: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable a page via a q=admin/build/pages/nojs/enable/ value or (2) disable a page via a q=admin/build/pages/nojs/disable/ value.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1547?
CVE-2010-1547 is considered a medium severity vulnerability due to its potential for CSRF attacks on administrator sessions.
How do I fix CVE-2010-1547?
To fix CVE-2010-1547, upgrade the Chaos Tool Suite (Ctools) module to version 6.x-1.4 or later.
What types of attacks can CVE-2010-1547 enable?
CVE-2010-1547 can enable cross-site request forgery (CSRF) attacks that may hijack authenticated administrator sessions.
Which versions of Ctools are affected by CVE-2010-1547?
CVE-2010-1547 affects all Ctools versions before 6.x-1.4, including 6.x-1.0 and its alpha, beta, and release candidate versions.
Is CVE-2010-1547 relevant for Drupal websites?
Yes, CVE-2010-1547 specifically affects Drupal sites using the Chaos Tool Suite module prior to version 6.x-1.4.