CVE-2015-3366: CSRF
Cross-site request forgery (CSRF) vulnerability in the Alfresco module before 6.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete an alfresco node via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3366?
CVE-2015-3366 has a medium severity rating due to its potential to allow unauthorized deletion of alfresco nodes.
How do I fix CVE-2015-3366?
To fix CVE-2015-3366, upgrade the Alfresco module in your Drupal installation to version 6.x-1.3 or later.
Which versions of Alfresco are affected by CVE-2015-3366?
CVE-2015-3366 affects all Alfresco module versions for Drupal prior to 6.x-1.3.
What type of attack is enabled by CVE-2015-3366?
CVE-2015-3366 enables a cross-site request forgery (CSRF) attack that can hijack user authentication.
Can CVE-2015-3366 impact user data?
Yes, CVE-2015-3366 can impact user data by allowing attackers to delete alfresco nodes on behalf of authenticated users.