logo

Database

Cross-site request forgery In drupal/project_browser

Description

The Project Browser module enables you to apply recipes and enable modules from the web user interface.

The module doesn't sufficiently validate admin actions to protect against cross-site request forgery attacks (CSRF).

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions