CVE-2012-2341: CSRF
Published May 18, 2012
·Updated
Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.
Affected Software
4 affected components
Rahul Singla Take Control=6.x-1.x
Rahul Singla Take Control=6.x-2.0-beta3
Rahul Singla Take Control=6.x-2.x
Drupal Drupal
Event History
May 18, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2341?
The severity of CVE-2012-2341 is rated as moderate due to its potential to allow cross-site request forgery attacks on specified users.
2
How do I fix CVE-2012-2341?
To fix CVE-2012-2341, update the Take Control module to version 6.x-2.2 or later.
3
What type of vulnerability is CVE-2012-2341?
CVE-2012-2341 is classified as a cross-site request forgery (CSRF) vulnerability.
4
Which software versions are affected by CVE-2012-2341?
CVE-2012-2341 affects Take Control module versions 6.x-2.x before 6.x-2.2 and 6.x-1.x.
5
What are the potential impacts of CVE-2012-2341?
The potential impacts of CVE-2012-2341 include unauthorized manipulation of files by hijacking user authentication.