Cross-site request forgery (CSRF) vulnerability in the order-management functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubercart | Ubercart | 5.x-1.0 (including) | 5.x-1.0 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha1 (including) | 5.x-1.0-alpha1 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha2 (including) | 5.x-1.0-alpha2 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha3 (including) | 5.x-1.0-alpha3 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha4 (including) | 5.x-1.0-alpha4 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha5 (including) | 5.x-1.0-alpha5 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha6 (including) | 5.x-1.0-alpha6 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha6b (including) | 5.x-1.0-alpha6b (including) |
Ubercart | Ubercart | 5.x-1.0-alpha6c (including) | 5.x-1.0-alpha6c (including) |
Ubercart | Ubercart | 5.x-1.0-alpha7 (including) | 5.x-1.0-alpha7 (including) |
Ubercart | Ubercart | 5.x-1.0-alpha7b (including) | 5.x-1.0-alpha7b (including) |
Ubercart | Ubercart | 5.x-1.0-alpha7c (including) | 5.x-1.0-alpha7c (including) |
Ubercart | Ubercart | 5.x-1.0-alpha7d (including) | 5.x-1.0-alpha7d (including) |
Ubercart | Ubercart | 5.x-1.0-alpha7e (including) | 5.x-1.0-alpha7e (including) |
Ubercart | Ubercart | 5.x-1.0-alpha8 (including) | 5.x-1.0-alpha8 (including) |
Ubercart | Ubercart | 5.x-1.0-beta1 (including) | 5.x-1.0-beta1 (including) |
Ubercart | Ubercart | 5.x-1.0-beta2 (including) | 5.x-1.0-beta2 (including) |
Ubercart | Ubercart | 5.x-1.0-beta3 (including) | 5.x-1.0-beta3 (including) |
Ubercart | Ubercart | 5.x-1.0-beta4 (including) | 5.x-1.0-beta4 (including) |
Ubercart | Ubercart | 5.x-1.0-beta5 (including) | 5.x-1.0-beta5 (including) |
Ubercart | Ubercart | 5.x-1.0-beta6 (including) | 5.x-1.0-beta6 (including) |
Ubercart | Ubercart | 5.x-1.0-beta7 (including) | 5.x-1.0-beta7 (including) |
Ubercart | Ubercart | 5.x-1.0-rc1 (including) | 5.x-1.0-rc1 (including) |
Ubercart | Ubercart | 5.x-1.0-rc2 (including) | 5.x-1.0-rc2 (including) |
Ubercart | Ubercart | 5.x-1.0-rc3 (including) | 5.x-1.0-rc3 (including) |
Ubercart | Ubercart | 5.x-1.0-rc4 (including) | 5.x-1.0-rc4 (including) |
Ubercart | Ubercart | 5.x-1.0-rc5 (including) | 5.x-1.0-rc5 (including) |
Ubercart | Ubercart | 5.x-1.1 (including) | 5.x-1.1 (including) |
Ubercart | Ubercart | 5.x-1.2 (including) | 5.x-1.2 (including) |
Ubercart | Ubercart | 5.x-1.3 (including) | 5.x-1.3 (including) |
Ubercart | Ubercart | 5.x-1.3-rc1 (including) | 5.x-1.3-rc1 (including) |
Ubercart | Ubercart | 5.x-1.4 (including) | 5.x-1.4 (including) |
Ubercart | Ubercart | 5.x-1.5 (including) | 5.x-1.5 (including) |
Ubercart | Ubercart | 5.x-1.6 (including) | 5.x-1.6 (including) |
Ubercart | Ubercart | 5.x-1.7 (including) | 5.x-1.7 (including) |
Ubercart | Ubercart | 5.x-1.8 (including) | 5.x-1.8 (including) |
Ubercart | Ubercart | 6.x-2.0 (including) | 6.x-2.0 (including) |
Ubercart | Ubercart | 6.x-2.0-beta1 (including) | 6.x-2.0-beta1 (including) |
Ubercart | Ubercart | 6.x-2.0-beta2 (including) | 6.x-2.0-beta2 (including) |
Ubercart | Ubercart | 6.x-2.0-beta3 (including) | 6.x-2.0-beta3 (including) |
Ubercart | Ubercart | 6.x-2.0-beta4 (including) | 6.x-2.0-beta4 (including) |
Ubercart | Ubercart | 6.x-2.0-beta5 (including) | 6.x-2.0-beta5 (including) |
Ubercart | Ubercart | 6.x-2.0-beta6 (including) | 6.x-2.0-beta6 (including) |
Ubercart | Ubercart | 6.x-2.0-dev (including) | 6.x-2.0-dev (including) |
Ubercart | Ubercart | 6.x-2.0-rc1 (including) | 6.x-2.0-rc1 (including) |
Ubercart | Ubercart | 6.x-2.0-rc2 (including) | 6.x-2.0-rc2 (including) |
Ubercart | Ubercart | 6.x-2.0-rc3 (including) | 6.x-2.0-rc3 (including) |
Ubercart | Ubercart | 6.x-2.0-rc4 (including) | 6.x-2.0-rc4 (including) |
Ubercart | Ubercart | 6.x-2.0-rc5 (including) | 6.x-2.0-rc5 (including) |
Ubercart | Ubercart | 6.x-2.0-rc6 (including) | 6.x-2.0-rc6 (including) |
Ubercart | Ubercart | 6.x-2.0-rc7 (including) | 6.x-2.0-rc7 (including) |