AI Score
Confidence
Low
EPSS
Percentile
70.3%
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.
drupal.org/node/348295
osvdb.org/50743
www.securityfocus.com/bid/32894
exchange.xforce.ibmcloud.com/vulnerabilities/52441