CVE-2007-5594: CSRF
Published Oct 19, 2007
·Updated
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
Affected Software
2 affected components
Drupal Drupal>=5.0<5.3
fedoraproject fedora=7
Remediation
Patch Available
Event History
Oct 19, 2007
CVE Published
11:17 PM
Oct 20, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5594?
CVE-2007-5594 is regarded as a moderate severity vulnerability due to its ability to allow user deletion via CSRF attacks.
2
How do I fix CVE-2007-5594?
To fix CVE-2007-5594, upgrade Drupal to version 5.3 or later to apply the necessary CSRF protections.
3
Which versions of Drupal are affected by CVE-2007-5594?
CVE-2007-5594 affects Drupal versions prior to 5.3.
4
What types of attacks are possible with CVE-2007-5594?
CVE-2007-5594 allows remote attackers to perform cross-site request forgery (CSRF) attacks to delete users.
5
Is there any specific software besides Drupal that is affected by CVE-2007-5594?
Yes, CVE-2007-5594 also affects Fedora, specifically version 7.