PT-2012-3804 · Drupal · Fivestar
Greg Knaddison
·
Published
2012-08-14
·
Updated
2012-08-15
·
CVE-2012-2096
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Fivestar module versions prior to 6.x-1.20 for Drupal
Description
The issue allows remote attackers to manipulate voting averages by providing a negative value in the
vote parameter, due to improper validation of voting data.Recommendations
For Fivestar module versions prior to 6.x-1.20, update to version 6.x-1.20 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing user input for the
vote parameter to prevent negative values.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fivestar