CVE-2012-3799: Blaine Lang Maestro

Medium severity, CVSS 5.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) change workflows or (2) insert cross-site scripting (XSS) sequences.

Affected products

  • Blaine Lang Maestro: version 7.x-1.0 only; version 7.x-1.1 only; version 7.x-1.x only

Published 2012-06-27. Last modified 2026-06-16.