First published: Fri Aug 31 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Commerceguys Commerce Reorder | <=7.x-1.0 | |
Commerceguys Commerce Reorder | =7.x-1.x-dev | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2116 has been rated as a high severity vulnerability due to its potential for remote exploitation and user authentication hijacking.
To fix CVE-2012-2116, update the Commerce Reorder module to version 7.x-1.1 or higher.
CVE-2012-2116 affects users of the Commerce Reorder module for Drupal versions before 7.x-1.1.
CVE-2012-2116 enables cross-site request forgery (CSRF) attacks that can hijack the authentication of users.
Yes, a patch is included in the updated version of the Commerce Reorder module, starting from version 7.x-1.1.