First published: Fri May 18 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
N-able Take Control | =6.x-1.x | |
N-able Take Control | =6.x-2.0-beta3 | |
N-able Take Control | =6.x-2.x | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-2341 is rated as moderate due to its potential to allow cross-site request forgery attacks on specified users.
To fix CVE-2012-2341, update the Take Control module to version 6.x-2.2 or later.
CVE-2012-2341 is classified as a cross-site request forgery (CSRF) vulnerability.
CVE-2012-2341 affects Take Control module versions 6.x-2.x before 6.x-2.2 and 6.x-1.x.
The potential impacts of CVE-2012-2341 include unauthorized manipulation of files by hijacking user authentication.