First published: Tue Mar 19 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Restful Web Services | >=7.x-1.0<7.x-1.2 | |
Restful Web Services | =7.x-2.0 | |
Restful Web Services | =7.x-2.0-alpha1 | |
Restful Web Services | =7.x-2.0-alpha2 | |
Restful Web Services | =7.x-2.0-alpha3 | |
Drupal | >=7.0<=7.82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0205 has a moderate severity level as it allows attackers to perform cross-site request forgery (CSRF) attacks.
To fix CVE-2013-0205, update the Restful Web Services module to version 7.x-1.2 or 7.x-2.0-alpha4 or later.
CVE-2013-0205 affects the Restful Web Services module versions prior to 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal.
CVE-2013-0205 is categorized as a cross-site request forgery (CSRF) vulnerability.
Users of Drupal with the affected versions of the Restful Web Services module can be impacted by CVE-2013-0205 as it allows remote attackers to hijack user authentication.