CVE-2015-3367: Patterns

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple cross-site request forgery (CSRF) vulnerabilities in the Patterns module before 7.x-2.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) restore, (2) publish, or (3) unpublish a pattern via unspecified vectors.

Affected products

  • Patterns Patterns: up to and including 7.x-2.1

Published 2015-04-21. Last modified 2026-06-17.