Drupal Maestro Module Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
24 Jun. 2012
Summary
The Maestro module for Drupal is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability.
Credit:
The information has been provided by Greg Knaddison and Stella Power.
The original article can be found at: http://www.securityfocus.com/bid/53836
An attacker can exploit the cross-site request-forgery issue to perform unauthorized actions in the context of a user's session. This may aid in other attacks. The attacker can exploit the cross-site scripting issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Vendor Status:
Drupal had issued an update for this vulnerability