CVE

Id
28951  
CVE No.
CVE-2007-5594  
Status
Candidate  
Description
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.  
Phase
Assigned (20071019)  
Votes
None (candidate not yet proposed)  
Comments