First published: Fri Nov 30 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
David Alkire Drag \& Drop Gallery | =6.x-1.5 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4478 is considered a medium severity vulnerability due to its potential for CSRF attacks targeting administrators.
To fix CVE-2012-4478, you should update the Drag & Drop Gallery module to version 6.x-1.6 or later.
CVE-2012-4478 affects users of the Drag & Drop Gallery module version 6.x-1.5 for Drupal.
CVE-2012-4478 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2012-4478 can be exploited remotely by attackers to hijack the authentication of administrators.