6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
0.001 Low
EPSS
Percentile
47.1%
This module enables you to expose Drupal entities as RESTful web services. It provides a machine-readable interface to exchange resources in JSON, XML and RDF.
The module doesn’t sufficiently verify POST requests thereby exposing a Cross Site Request Forgery vulnerability.
This vulnerability is mitigated by the fact that an attacker must trick an authenticated user onto a page with a site-specific malicious HTML form submission.
CVE: CVE-2012-5556
Drupal core is not affected. If you do not use the contributed RESTful Web Services module, there is nothing you need to do.
Install the latest version:
Also see the RESTful Web Services project page.