Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-058
HistoryApr 11, 2012 - 12:00 a.m.

SA-CONTRIB-2012-058 - Fivestar - Input Validation

2012-04-1100:00:00
Drupal Security Team
www.drupal.org
9

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

0.005 Low

EPSS

Percentile

77.5%

CVE: CVE-2012-2096

The Fivestar module enables you to add a voting widget to nodes and comments.

The module does not sufficiently validate all votes passed by the asynchronous voting widget allowing a malicious user to improperly modify voting averages.

Versions affected

  • Fivestar 6.x-1.x versions prior to 6.x-1.20

Drupal core is not affected. If you do not use the contributed Fivestar module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Fivestar module for Drupal 6.x, upgrade to Fivestar 6.x-1.20

Also see the Fivestar project page.

Reported by

Fixed by

Coordinated by

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

0.005 Low

EPSS

Percentile

77.5%

Related for DRUPAL-SA-CONTRIB-2012-058