CVE-2008-0271

Drupal Bueditor < 4.7.x-1.0 - CSRF

Title source: rule

Description

The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.

Scores

EPSS 0.0014
EPSS Percentile 34.6%

Classification

CWE
CWE-352
Status draft

Affected Products (1)

drupal/bueditor < 4.7.x-1.0

Timeline

Published Jan 15, 2008
Tracked Since Feb 18, 2026