Lucene search

K
cve[email protected]CVE-2009-4517
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4517

2022-10-0316:24:03
CWE-352
web.nvd.nist.gov
20
cve-2009-4517
cross-site request forgery
csrf
drupal
faq ask module
unpublished content
authentication hijacking

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.3%

Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that access unpublished content.

Affected configurations

NVD
Node
nanwichfaq_askMatch5.x-1.0
OR
nanwichfaq_askMatch5.x-1.0beta1
OR
nanwichfaq_askMatch5.x-1.0beta2
OR
nanwichfaq_askMatch5.x-1.0beta3
OR
nanwichfaq_askMatch5.x-1.0beta4
OR
nanwichfaq_askMatch5.x-1.1
OR
nanwichfaq_askMatch5.x-1.2
OR
nanwichfaq_askMatch5.x-1.3
OR
nanwichfaq_askMatch5.x-1.xdev
OR
nanwichfaq_askMatch6.x-1.0
OR
nanwichfaq_askMatch6.x-1.0beta1
OR
nanwichfaq_askMatch6.x-1.1
OR
nanwichfaq_askMatch6.x-1.2
OR
nanwichfaq_askMatch6.x-1.xdev
OR
nanwichfaq_askMatch6.x-2.0alpha1
OR
nanwichfaq_askMatch6.x-2.xdev
AND
drupaldrupal

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.3%

Related for CVE-2009-4517