6.8
CVSSv2

CVE-2012-2097

Published: 14/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x prior to 6.x-2.10 and 7.x-2.x prior to 7.x-2.0 for Drupal allows remote malicious users to hijack the authentication of arbitrary users for requests involving "submitting saved results to a node."

Vulnerable Product Search on Vulmon Subscribe to Product

larry_garfield autosave 6.x-2.5

larry_garfield autosave 6.x-2.4

larry_garfield autosave 6.x-2.7

larry_garfield autosave 6.x-2.6

larry_garfield autosave 6.x-2.x

larry_garfield autosave 7.x-2.x

larry_garfield autosave

larry_garfield autosave 6.x-2.8

larry_garfield autosave 6.x-2.1

larry_garfield autosave 6.x-2.0

larry_garfield autosave 6.x-2.3

larry_garfield autosave 6.x-2.2