Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the local translation submission interface.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Localization_client | Drupal | * | 5.x-1.0 (including) |
Localization_client | Drupal | * | 6.x-1.5 (including) |
Localization_client | Drupal | 5.x-1.xdev (including) | 5.x-1.xdev (including) |
Localization_client | Drupal | 6.x-1.0 (including) | 6.x-1.0 (including) |
Localization_client | Drupal | 6.x-1.1 (including) | 6.x-1.1 (including) |
Localization_client | Drupal | 6.x-1.2 (including) | 6.x-1.2 (including) |
Localization_client | Drupal | 6.x-1.3 (including) | 6.x-1.3 (including) |
Localization_client | Drupal | 6.x-1.4 (including) | 6.x-1.4 (including) |
Localization_client | Drupal | 6.x-1.xdev (including) | 6.x-1.xdev (including) |
Localization_server | Drupal | * | 5.x-1.0alpha4 (including) |
Localization_server | Drupal | * | 6.x-1.0alpha1 (including) |
Localization_server | Drupal | 5.x-1.0alpha1 (including) | 5.x-1.0alpha1 (including) |
Localization_server | Drupal | 5.x-1.0alpha2 (including) | 5.x-1.0alpha2 (including) |
Localization_server | Drupal | 5.x-1.0alpha3 (including) | 5.x-1.0alpha3 (including) |
Localization_server | Drupal | 5.x-1.xdev (including) | 5.x-1.xdev (including) |
Localization_server | Drupal | 6.x-1.xdev (including) | 6.x-1.xdev (including) |