Drupal Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2007-6752 - Vulnerability Database

Drupal Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2007-6752

Medium
Reference: CVE-2007-6752
Title: Drupal Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

DISPUTED Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue by considering the quotsecurity benefit against platform complexity and performance impactquot and concluding that a change to the logout behavior is not planned because quotfor most sites it is not worth the trade-off.quot