Back

HIGH

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF

Published Mar 16, 2017

Description

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner drupal
Published Mar 16, 2017
Updated Aug 5, 2024
Reserved Feb 28, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-GXXQ-FHC7-3JV9