PT-2012-5423 · Drupal · Security Questions Module+1
Joshua Brauer
·
Published
2012-11-30
·
Updated
2012-12-03
·
CVE-2012-4475
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Security Questions module for Drupal versions 6.x-1.x before 6.x-1.1
Security Questions module for Drupal versions 7.x-1.x before 7.x-1.1
Description
The issue allows remote attackers to edit an arbitrary user's questions and answers due to improper access restriction in the Security Questions module.
Recommendations
For Security Questions module for Drupal versions 6.x-1.x before 6.x-1.1, update to version 6.x-1.1 or later.
For Security Questions module for Drupal versions 7.x-1.x before 7.x-1.1, update to version 7.x-1.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal
Security Questions Module