Release date:
Updated on: 2012-10-03
Affected Systems:
Drupal Admin: hover 7.x
Drupal Admin: hover 6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51388
Cve id: CVE-2012-1631
Admin of Drupal: the hover module can add management links to nodes and Prevent Users From editing content.
Admin: the hover module for Drupal 6.x, 7.x, and other versions have the CSRF vulnerability, which allows remote attackers to hijack administrator authentication requests.
<* Source: Ivo Van Geertruyen
Link: http://xforce.iss.net/xforce/xfdb/72386
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Drupal
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://drupal.org/