CyberRota Analysis
AI analysis pending.
CVE
CVE-2012-0825
Severity
MEDIUM
CVSS
6.8
EPSS
1.98%
Exchange
Original NVD Description
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.