User access rules can be added or deleted upon accessing a properly formatted URL, making such modifications vulnerable to cross site request forgeries (CSRF).
Credit:
The information has been provided by Barry Jaspan.
User access rules can be added or deleted upon accessing a properly formatted URL, making such modifications vulnerable to cross site request forgeries (CSRF). This may lead to unintended addition or deletion of an access rule when a sufficiently privileged user visits a page or site created by a malicious person.
This bug affects both Drupal 5.x and 6.x.
Vendor Status:
Drupal issued an update for this vulnerability