Description

Like/Dislike module can be used to Like and Dislike actions on any content. It is powered by Drupal field concept.

The module does not verify user intent on like/dislike links thereby exposing a Cross Site Request Forgery (CSRF) vulnerability.

CVE identifier(s) issued

  • A CVE identifier will be requested, and added upon issuance, in accordance with Drupal Security Team processes.

Versions affected

  • All versions of like/dislike module.

Drupal core is not affected. If you do not use the contributed Like/Dislike module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Like/Dislike project page.

Reported by

Fixed by

Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.

Follow the Drupal Security Team on Twitter at https://twitter.com/drupalsecurity