The OpenID module in Drupal 6 allows users to create an account or log into a Drupal site using one or more OpenID identities.
The core OpenID module does not correctly implement Form API for the form that allows one to link user accounts with OpenID identifiers. A malicious user is therefore able to use cross site request forgeries to add attacker controlled OpenID identities to existing accounts. These OpenID identities can then be used to gain access to the affected accounts.
This issue affects Drupal 6.x only.
Vendor Status:
Drupal issued an update for this vulnerability