Drupal Commerce Balanced Payment Module Multiple Security Vulnerabilities

The Commerce Balanced Payments module for Drupal is prone to a cross-site scripting vulnerability and multiple cross-site request-forgery vulnerabilities because it fails to sufficiently sanitize user-supplied input.

An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, or perform unauthorized actions. Other attacks may also be possible.


Privacy Statement
Copyright 2010, SecurityFocus