CSRF Vulnerability in Drupal Decisions Module Allows Unauthorized Voter Removal

CSRF Vulnerability in Drupal Decisions Module Allows Unauthorized Voter Removal

CVE-2015-4383 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Cross-site request forgery (CSRF) vulnerability in the Decisions module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that remove individual voters via unspecified vectors.

Learn more about our User Device Pen Test.