PT-2012-5433 · Drupal · Subuser Module

Joshua Brauer

·

Publicado

2012-11-02

·

Atualizado

2012-11-05

·

CVE-2012-4487

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Subuser module versions prior to 6.x-1.8 for Drupal
Description The issue concerns the Subuser module for Drupal, where it fails to properly check switch subuser permissions. This allows remote authenticated parent users to change their role by switching to a subuser they created.
Recommendations For versions prior to 6.x-1.8, update to version 6.x-1.8 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4487

Produtos afetados

Subuser Module