Vulnerable Systems:
* Drupal 4.7.x before version 4.7.11.
* Drupal 5.x before version 5.6.
The aggregator module fetches items from RSS feeds and makes them available on the site. The module provides an option to remove items from a particular feed. This has been implemented as a simple GET request and is therefore vulnerable to cross site request forgeries. For example: Should a privileged user view a page containing an tag with a specially constructed src pointing to a remove items URL, the items would be removed.
Vendor Status:
Drupal issued an update for this vulnerability