CVE-2008-3221

NONECVSS 0.0
0.0
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No confirmed exploitation signals yet
CISA-KEV: Not listedEPSS: 1%CVSS: Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVSS v3
EG Score
0.0(none)
EG Risk
EPSS
63.2%
KEV
Not listed

Published

July 18, 2008

Last Modified

April 23, 2026

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Frequently asked(4)

What is CVE-2008-3221?
CVE-2008-3221 is a none vulnerability published on July 18, 2008. Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
When was CVE-2008-3221 disclosed?
CVE-2008-3221 was first published in the National Vulnerability Database on July 18, 2008, with the most recent update on April 23, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2008-3221 actively exploited?
CVE-2008-3221 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 63.2% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
How do I remediate CVE-2008-3221?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2008-3221, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2008-3221

Explore →

Is Your Infrastructure Affected by CVE-2008-3221?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.