CVE-2013-6385: Code Injection
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6385?
CVE-2013-6385 is classified as a moderate severity vulnerability that can potentially lead to arbitrary code execution.
How do I fix CVE-2013-6385?
To fix CVE-2013-6385, update Drupal to version 6.29 or 7.24 or later.
What versions of Drupal are affected by CVE-2013-6385?
CVE-2013-6385 affects Drupal 6.x versions prior to 6.29 and 7.x versions prior to 7.24.
What kind of attacks can CVE-2013-6385 allow?
CVE-2013-6385 could allow remote attackers to exploit the vulnerability to execute arbitrary code under certain conditions.
Is there a workaround for CVE-2013-6385?
While upgrading is the best method to mitigate CVE-2013-6385, specific third-party module configurations may be temporarily modified to minimize risk until an update is applied.