{"id":"UBUNTU-CVE-2007-6752","details":"Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI.  NOTE: the vendor disputes the significance of this issue, by considering the \"security benefit against platform complexity and performance impact\" and concluding that a change to the logout behavior is not planned because \"for most sites it is not worth the trade-off.","modified":"2025-09-08T16:42:50Z","published":"2012-03-28T10:54:00Z","upstream":["CVE-2007-6752"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2007-6752"},{"type":"REPORT","url":"http://www.exploit-db.com/exploits/18564/"},{"type":"REPORT","url":"http://packetstormsecurity.org/files/110404/drupal712-xsrf.txt"},{"type":"REPORT","url":"http://ivanobinetti.blogspot.it/2012/03/drupal-cms-712-latest-stable-release.html"},{"type":"REPORT","url":"http://groups.drupal.org/node/216314"},{"type":"REPORT","url":"http://drupal.org/node/144538"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2007-6752"}],"affected":[{"package":{"name":"drupal7","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/drupal7@7.26-1ubuntu0.1+esm3?arch=source&distro=esm-infra-legacy/trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.23-1","7.24-1","7.24-2","7.26-1","7.26-1ubuntu0.1","7.26-1ubuntu0.1+esm1","7.26-1ubuntu0.1+esm2","7.26-1ubuntu0.1+esm3"],"ecosystem_specific":{"binaries":[{"binary_name":"drupal7","binary_version":"7.26-1ubuntu0.1+esm3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2007/UBUNTU-CVE-2007-6752.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"low"}]}