CVE-2012-2096
Published Aug 14, 2012The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in…
Vendor/product archive
2 CVEs tagged to lullabot / fivestar_module_for_drupal — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in…
Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack…