CVE-2012-5556: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and 7.x-2.x before 7.x-2.0-alpha3 for Drupal allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5556?
CVE-2012-5556 is rated as a critical vulnerability due to its potential to allow remote attackers to hijack user authentication.
How do I fix CVE-2012-5556?
To fix CVE-2012-5556, you should update the Restful Web Services module to version 7.x-1.1 or later for 7.x-1.x, and 7.x-2.0-alpha3 or later for 7.x-2.x.
What are the potential impacts of CVE-2012-5556?
The potential impacts of CVE-2012-5556 include unauthorized access and actions on behalf of authenticated users due to CSRF vulnerabilities.
Which versions of Restful Web Services are affected by CVE-2012-5556?
Versions 7.x-1.0, 7.x-1.0-beta1, 7.x-1.0-beta2, 7.x-1.x-dev, 7.x-2.0-alpha1, 7.x-2.0-alpha2, and 7.x-2.x-dev are affected by CVE-2012-5556.
Who can be impacted by CVE-2012-5556?
Any user of Drupal installations with the affected versions of the Restful Web Services module can be impacted by CVE-2012-5556.