CVE-2015-4391: CSRF
Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of users for requests that delete reports via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4391?
CVE-2015-4391 is classified as a medium severity vulnerability due to its potential to allow unauthorized deletion of reports.
How do I fix CVE-2015-4391?
To fix CVE-2015-4391, upgrade to CiviCRM private report module version 6.x-1.2 or 7.x-1.3 or later.
Which versions of CiviCRM are affected by CVE-2015-4391?
CVE-2015-4391 affects CiviCRM private report module versions 6.x-1.0, 6.x-1.1, 7.x-1.0, and 7.x-1.1.
What types of attacks are possible with CVE-2015-4391?
CVE-2015-4391 allows remote attackers to perform cross-site request forgery (CSRF) attacks to hijack user authentication for report deletion.
Is there a patch for CVE-2015-4391?
Yes, there are patches available in the updated versions of the CiviCRM private report module that address CVE-2015-4391.