Session Reversion Vulnerability in Token Authentication Module for Drupal

Session Reversion Vulnerability in Token Authentication Module for Drupal

CVE-2012-2720 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attackers to perform requests with extra privileges.

Learn more about our User Device Pen Test.