Unrated severityNVD Advisory· Published Jul 22, 2009· Updated Apr 23, 2026
CVE-2009-2572
CVE-2009-2572
Description
Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.
Affected products
15cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.9:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.9:*:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.10:*:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.11:*:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.11:beta1:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.11:beta2:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.11:beta3:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.11:beta4:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.12:*:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:5.x-1.13:*:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.11:beta3:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.11:beta4:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.11:beta5:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.12:*:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.12:beta1:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.13:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- drupal.org/node/449042nvdPatchVendor Advisory
- www.vupen.com/english/advisories/2009/1215nvdPatchVendor Advisory
- drupal.org/node/449026nvdVendor Advisory
- drupal.org/node/449028nvdVendor Advisory
- secunia.com/advisories/34956nvdVendor Advisory
- osvdb.org/54154nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/50245nvd
News mentions
0No linked articles in our index yet.