7.5
CVSSv3

CVE-2017-6379

Published: 16/03/2017 Updated: 12/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Some administrative paths in Drupal 8.2.x prior to 8.2.7 did not include protection for CSRF. This would allow an malicious user to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 8.2.5

drupal drupal 8.2.6

drupal drupal 8.2.1

drupal drupal 8.2.2

drupal drupal 8.2.3

drupal drupal 8.2.4

drupal drupal 8.2.0