PT-2012-3804 · Drupal · Fivestar

Greg Knaddison

·

Published

2012-08-14

·

Updated

2012-08-15

·

CVE-2012-2096

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fivestar module versions prior to 6.x-1.20 for Drupal
Description The issue allows remote attackers to manipulate voting averages by providing a negative value in the vote parameter, due to improper validation of voting data.
Recommendations For Fivestar module versions prior to 6.x-1.20, update to version 6.x-1.20 or later to resolve the issue. As a temporary workaround, consider validating and sanitizing user input for the vote parameter to prevent negative values.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2096

Affected Products

Fivestar