CVE-2013-0320
 
Severity Score
5.1
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors.
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el Administrador de Taxonomía (taxonomy_manager) módulo v6.x-2.x antes v6.x-2.2 y v7.x-1.x antes v7.x-1.0-rc1 para Drupal permite a atacantes remotos secuestrar a la autenticación de usuarios con el permiso 'administer taxonomy' a ??través de vectores no especificados.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-12-06 CVE Reserved
- 2013-03-27 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://drupalcode.org/project/taxonomy_manager.git/commitdiff/2d05801 | X_refsource_confirm | |
http://drupalcode.org/project/taxonomy_manager.git/commitdiff/595f1b3 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2013/02/21/5 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/node/1922168 | 2013-03-28 | |
http://drupal.org/node/1922170 | 2013-03-28 | |
http://drupal.org/node/1922410 | 2013-03-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 6.x-2.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "6.x-2.0" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 6.x-2.1 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "6.x-2.1" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 6.x-2.x Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "6.x-2.x" | dev |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.0" | alpha1 |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.0" | alpha2 |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.0" | alpha3 |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.0" | alpha4 |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.0" | beta1 |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.0" | beta2 |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.0 Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.0" | beta3 |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|
Mattias Hutterer Search vendor "Mattias Hutterer" | Taxonomy Manager Search vendor "Mattias Hutterer" for product "Taxonomy Manager" | 7.x-1.x Search vendor "Mattias Hutterer" for product "Taxonomy Manager" and version "7.x-1.x" | dev |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | - | - |
Safe
|