Description
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin Customer Service Software & Support Ticket System Cross-Site Scripting (5.10.3)
WordPress Plugin White Label CMS Cross-Site Request Forgery (1.5)
WordPress Plugin Bulk change of posts terms and post types Cross-Site Scripting (1.0)
Oracle Application Server Other Vulnerability (CVE-2005-3449)