Security Advisory

CVE-2015-1568

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-02-09 17:00:00
Last updated 2024-08-06 04:47:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote attackers to hijack the authentication of users with the "edit gd infinite scroll settings" permission for requests that delete settings via unspecified vectors.