CVE-2010-1547 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities within the Chaos Tool Suite (CTools) module for Drupal, specifically versions 6.x before 6.x-1.4. An attacker could exploit these flaws to hijack an administrator's authenticated session, enabling or disabling pages through specific URL parameters. With a CVSS score of 6.8, this vulnerability is rated as medium severity due to its network-based attack vector and medium attack complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. The EPSS score is very low, indicating a minimal likelihood of exploitation. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also absent, suggesting a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.x-1.0CPE matchmatch criteria | cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:*:*:*:*:drupal:*:* | ||
6.x-1.0CPE matchmatch criteria | cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:alpha1:*:*:*:drupal:*:* | ||
6.x-1.0CPE matchmatch criteria | cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:alpha2:*:*:*:drupal:*:* | ||
6.x-1.0CPE matchmatch criteria | cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:alpha3:*:*:*:drupal:*:* | ||
6.x-1.0CPE matchmatch criteria | cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:beta1:*:*:*:drupal:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.