CVE-2012-2116

medium
Published 2012-08-31 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/48912

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://drupalcode.org/project/commerce_reorder.git/commit/bf060ab

Application impact

VendorProductVersionsFixed
commerceguyscommerce_reorder{"endIncluding":"7.x-1.0"}
commerceguyscommerce_reorder7.x-1.x
drupaldrupal-

References

CWEs

CWE-352

Verify integrity in audit chain (admin only). AS-IS.