Node Basket Module For Drupal Cross-Site Request Forgery Vulnerabilities
2 Oct. 2015
Summary
Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add or (2) remove nodes from a basket
Vulnerable Systems:
* Node basket module for Drupal
Node basket module for Drupal is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to add or remove nodes of the basket. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.