CVE-2013-0205: CSRF
Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0205?
CVE-2013-0205 has a moderate severity level as it allows attackers to perform cross-site request forgery (CSRF) attacks.
How do I fix CVE-2013-0205?
To fix CVE-2013-0205, update the Restful Web Services module to version 7.x-1.2 or 7.x-2.0-alpha4 or later.
What software is affected by CVE-2013-0205?
CVE-2013-0205 affects the Restful Web Services module versions prior to 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal.
What type of vulnerability is CVE-2013-0205?
CVE-2013-0205 is categorized as a cross-site request forgery (CSRF) vulnerability.
Who can be impacted by CVE-2013-0205?
Users of Drupal with the affected versions of the Restful Web Services module can be impacted by CVE-2013-0205 as it allows remote attackers to hijack user authentication.