Security Advisory

CVE-2017-6379

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-03-16 14:00:00
Last updated 2024-08-05 15:25:49
Assigner drupal
CVSS score not scored
State PUBLISHED

Description

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.