CVE-2012-2116 Information
Feb 14, 2021
cve
Description
Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart.
Reference
http://drupal.org/node/1538198 http://drupalcode.org/project/commerce_reorder.git/commit/bf060ab http://secunia.com/advisories/48912 http://www.openwall.com/lists/oss-security/2012/04/18/11 http://www.openwall.com/lists/oss-security/2012/04/19/1
Share on: