The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2015-08-24T14:00:00

Updated: 2024-08-06T07:29:23.161Z

Reserved: 2015-08-24T00:00:00

Link: CVE-2015-6660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-08-24T14:59:17.540

Modified: 2016-12-24T02:59:33.590

Link: CVE-2015-6660

cve-icon Redhat

No data.