CVE

Id
80629  
CVE No.
CVE-2015-3352  
Status
Candidate  
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the Jammer module before 6.x-1.8 and 7.x-1.x before 7.x-1.4 for Drupal allow remote attackers to hijack the authentication of administrators for requests that delete a setting for (1) hidden form elements or (2) status messages via unspecified vectors, related to "report administration."  
Phase
Assigned (20150421)  
Votes
None (candidate not yet proposed)  
Comments