MEDIUM · 6.8

CVE-2012-2057

Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors rel...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MiuraUbercart Bulk Stock Updater-
DrupalDrupal-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2057?

CVE-2012-2057 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors rel...

How severe is CVE-2012-2057?

CVE-2012-2057 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2057?

Check the references section above for vendor advisories and patch information. Affected products include: Miura Ubercart Bulk Stock Updater, Drupal Drupal.