Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted request.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2015-08-18T17:00:00
Updated: 2024-08-06T06:50:02.856Z
Reserved: 2015-07-10T00:00:00
Link: CVE-2015-5508
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-08-18T18:00:13.817
Modified: 2024-11-21T02:33:10.240
Link: CVE-2015-5508
Redhat
No data.