Project
Date
Severity
Moderately Critical
Vulnerability
Cross Site Request Forgery
Affected versions
<7.x-1.2
Description
The Taxonomy File Tree module lets privileged group members archive folders and files and later restore them to their previous location in the tree.
The restore callbacks are reachable over a normal GET request and change data by moving taxonomy terms and saving nodes, yet they carry no token to prove the request was intended, so a forged request loaded by a logged in user who holds the archive permission will silently restore and move elements.
This vulnerability is mitigated by the fact that the request only succeeds for a user who holds the folder archive permission and requires the identifier of an archived element.
Solution
Install the latest version.
If you use the Taxonomy File Tree module for Drupal 7, upgrade to Taxonomy File Tree 7.x-1.2:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES