Description
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH Product Size Charts for WooCommerce Security Bypass (1.1.11)
WordPress Plugin Customer Service Software & Support Ticket System Cross-Site Scripting (5.10.3)
Envoy Proxy Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27492)
WordPress Plugin Autoptimize Multiple Vulnerabilities (2.7.6)