Your submission was sent successfully! Close

CVE-2015-6660

Published: 24 August 2015

The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."

Priority

Medium

Status

Package Release Status
drupal6
Launchpad, Ubuntu, Debian
Upstream
Released (6.37)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Does not exist

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

drupal7
Launchpad, Ubuntu, Debian
Upstream
Released (7.39-1)
Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(7.44-1ubuntu1~16.04.0)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was needed)