Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2012-060
HistoryApr 18, 2012 - 12:00 a.m.

SA-CONTRIB-2012-060 - Commerce Reorder - Cross Site Request Forgery

2012-04-1800:00:00
Drupal Security Team
www.drupal.org
3

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

53.4%

CVE: CVE-2012-2116

The Commerce Reorder module enables you to reorder previously purchased products for Drupal Commerce.

The module does not sufficiently protect the re-order URL against Cross Site Request Forgery (CSRF), allowing a malicious user to trick someone into adding unwanted items to their shopping cart.

This vulnerability is mitigated by by the fact that while items can be placed in a shopping cart, the user still has to complete the checkout process, and by the fact that re-ordering is restricted by access to the “source” order.

Versions affected

  • Commerce Reorder versions prior to 7.x-1.1.

Drupal core is not affected. If you do not use the contributed Commerce Reorder module, there is nothing you need to do.

Solution

Install the latest version:

Also see the Commerce Reorder project page.

Reported by

  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team

Fixed by

  • Pedro Cambra (pcambra), the module maintainer
  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team

Coordinated by

  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.002 Low

EPSS

Percentile

53.4%

Related for DRUPAL-SA-CONTRIB-2012-060