CVE-2008-0272
Drupal - CSRF
Title source: ruleDescription
Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.
References (9)
Scores
EPSS
0.0034
EPSS Percentile
56.1%
Classification
CWE
CWE-352
Status
draft
Affected Products (48)
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 33 more
Timeline
Published
Jan 15, 2008
Tracked Since
Feb 18, 2026