"value":"Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Cross-Site Request Forgery "
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Mozilla",
"product":{
"product_data":[
{
"product_name":"Persona",
"version":{
"version_data":[
{
"version_value":"7.x-1.x versions prior to 7.x-1.11"