CVE-2013-4227: CSRF
Cross-site request forgery (CSRF) vulnerability in the personaxsrftoken function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4227?
CVE-2013-4227 is classified as a medium severity vulnerability due to its potential for cross-site request forgery attacks.
How do I fix CVE-2013-4227?
To mitigate CVE-2013-4227, upgrade the Mozilla Persona module to version 7.x-1.11 or later.
Who is affected by CVE-2013-4227?
CVE-2013-4227 affects users of the Mozilla Persona module versions prior to 7.x-1.11 in Drupal.
What type of vulnerability is CVE-2013-4227?
CVE-2013-4227 is a cross-site request forgery (CSRF) vulnerability.
What can attackers do with CVE-2013-4227?
Attackers exploiting CVE-2013-4227 can hijack the authentication of arbitrary users by using a malformed security token.