- Advisory ID: DRUPAL-SA-CONTRIB-2016-056
- Project: Like/Dislike (third-party module)
- Version: 7.x
- Date: 2016-November-02
- Security risk: 15/25 ( Moderately Critical) AC:None/A:None/CI:Some/II:Some/E:Theoretical/TD:All
- Cross Site Request Forgery
Description
Like/Dislike module can be used to Like and Dislike actions on any content. It is powered by Drupal field concept.
CVE identifier(s) issued
- A CVE identifier will be requested, and added upon issuance, in accordance with Drupal Security Team processes.
Versions affected
- All versions of like/dislike module.
Drupal core is not affected. If you do not use the contributed Like/Dislike module, there is nothing you need to do.
Solution
If you use the like/dislike module for Drupal 7.x you should uninstall it.
Also see the Like/Dislike project page.
Reported by
Fixed by
Not applicable.
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.
Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.
Follow the Drupal Security Team on Twitter at https://twitter.com/drupalsecurity