CVE-2017-6379
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
HIGH · CVSS 7.5
EPSS 0.00191
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0