CVE-2012-2097: Larry Garfield Autosave
Medium severity, CVSS 6.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests involving "submitting saved results to a node."
Affected products
- Larry Garfield Autosave: up to and including 6.x-2.9; version 6.x-2.0 only; version 6.x-2.1 only; version 6.x-2.2 only; version 6.x-2.3 only; version 6.x-2.4 only; …
Published 2012-08-14. Last modified 2026-06-16.