CVE-2007-6752

Drupal < 7.12 - Cross-Site Request Forgery via User Logout URI

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6752. PoCs published by Ivano Binetti.

AI-analyzed exploit summary This exploit demonstrates CSRF vulnerabilities in Drupal CMS 7.12, allowing an attacker to add an administrator account or force logout of an administrator by tricking them into visiting a crafted webpage. The exploit leverages poor session checking and lack of HTTP referer validation.

Description

Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off.

Exploits (1)

exploitdb WORKING POC
by Ivano Binetti · textwebappsphp
https://www.exploit-db.com/exploits/18564

This exploit demonstrates CSRF vulnerabilities in Drupal CMS 7.12, allowing an attacker to add an administrator account or force logout of an administrator by tricking them into visiting a crafted webpage. The exploit leverages poor session checking and lack of HTTP referer validation.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Drupal CMS 7.12 (and lower)
No auth needed
Prerequisites: Victim must visit a crafted webpage · Attacker must know valid form_build_id and form_token values
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory x_refsource_misc
http://groups.drupal.org/node/216314
Vendor Advisory x_refsource_misc
http://drupal.org/node/144538
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18564/

Scores

EPSS 0.0375
EPSS Percentile 88.5%

Details

CWE
CWE-352
Status published
Products (49)
drupal/drupal 4.0
drupal/drupal 4.0.0
drupal/drupal 4.1.0
drupal/drupal 4.2.0_rc
drupal/drupal 4.4
drupal/drupal 4.4.0
drupal/drupal 4.4.1
drupal/drupal 4.4.2
drupal/drupal 4.4.3
drupal/drupal 4.5
... and 39 more
Published Mar 28, 2012
Tracked Since Feb 18, 2026