Unrated severityNVD Advisory· Published Aug 14, 2012· Updated Apr 29, 2026
CVE-2012-2096
CVE-2012-2096
Description
The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.
Affected products
2cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.20:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.20:*:*:*:*:*:*:*
- cpe:2.3:a:lullabot:fivestar_module_for_drupal:6.x-1.x:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- drupal.org/node/1528600nvdPatch
- drupal.org/node/1528614nvdPatchVendor Advisory
- www.securityfocus.com/bid/52984nvdPatch
- drupalcode.org/project/fivestar.git/commitdiff/75dba2cnvdExploitPatch
- secunia.com/advisories/48788nvdVendor Advisory
- www.openwall.com/lists/oss-security/2012/04/11/4nvd
- www.openwall.com/lists/oss-security/2012/04/12/2nvd
News mentions
0No linked articles in our index yet.