Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
| Software | From | Fixed in |
|---|---|---|
| services_project / services | 6.x-3.0 | 6.x-3.0.x |
| services_project / services | 6.x-3.1 | 6.x-3.1.x |
| services_project / services | 6.x-3.2 | 6.x-3.2.x |
| services_project / services | 6.x-3.3 | 6.x-3.3.x |
| services_project / services | 7.x-3.0 | 7.x-3.0.x |
| services_project / services | 7.x-3.1 | 7.x-3.1.x |
| services_project / services | 7.x-3.2 | 7.x-3.2.x |
| services_project / services | 7.x-3.3 | 7.x-3.3.x |