Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
We have discovered 134,723 live websites that are affected by CVE-2017-6379.
Product | |
Category | Content Management System |
Vulnerable Domains | 134,723 live websites (53.63% of Drupal install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 38 versions ( 12.46% of all versions) |
![]() | 42,235 websites |
![]() | 13,961 websites |
![]() | 11,936 websites |
![]() | 10,402 websites |
![]() | 4,254 websites |
![]() | 3,942 websites |
![]() | 3,693 websites |
![]() | 3,388 websites |
![]() | 2,843 websites |
![]() | 2,504 websites |
.com | 37,065 websites |
.org | 11,566 websites |
.ru | 9,895 websites |
.de | 7,241 websites |
.fr | 4,933 websites |
.be | 4,362 websites |
.edu | 4,036 websites |
.net | 3,308 websites |
.it | 2,937 websites |
.nl | 2,766 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.org | ![]() | *** | |
***.org | ![]() | *,*** | |
********.gov | ![]() | *,*** | |
******.gov | ![]() | *,*** | |
***.**.gov | ![]() | *,*** | |
******.edu | ![]() | *,*** | |
***.gov | ![]() | *,*** | |
****.org | ![]() | *,*** | |
***.com | ![]() | *,*** | |
*******.com | ![]() | *,*** |
FAQ