PT-2012-5423 · Drupal · Security Questions Module+1
Joshua Brauer
·
Publicado
2012-11-30
·
Atualizado
2012-12-03
·
CVE-2012-4475
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Security Questions module for Drupal versions 6.x-1.x before 6.x-1.1
Security Questions module for Drupal versions 7.x-1.x before 7.x-1.1
Description
The issue allows remote attackers to edit an arbitrary user's questions and answers due to improper access restriction in the Security Questions module.
Recommendations
For Security Questions module for Drupal versions 6.x-1.x before 6.x-1.1, update to version 6.x-1.1 or later.
For Security Questions module for Drupal versions 7.x-1.x before 7.x-1.1, update to version 7.x-1.1 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal
Security Questions Module