Medium
CVSS 6.8
Overview
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack ses...
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: