CVE-2012-5557
Summary
| CVE | CVE-2012-5557 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-12-03 21:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain operations, as demonstrated by changing a password. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Drupal | - | All | All | All |
| Application | User Read-only Project | User Readonly | 6.x-1.0 | All | All | All |
| Application | User Read-only Project | User Readonly | 6.x-1.1 | All | All | All |
| Application | User Read-only Project | User Readonly | 6.x-1.2 | All | All | All |
| Application | User Read-only Project | User Readonly | 6.x-1.3 | All | All | All |
| Application | User Read-only Project | User Readonly | 6.x-1.x | dev | All | All |
| Application | User Read-only Project | User Readonly | 7.x-1.0 | All | All | All |
| Application | User Read-only Project | User Readonly | 7.x-1.1 | All | All | All |
| Application | User Read-only Project | User Readonly | 7.x-1.2 | All | All | All |
| Application | User Read-only Project | User Readonly | 7.x-1.3 | All | All | All |
| Application | User Read-only Project | User Readonly | 7.x-1.x | dev | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| user_readonly 6.x-1.4 | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch |
| SA-CONTRIB-2012-163 - User Read-Only - Permission escalation | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch, Vendor Advisory |
| oss-security - Re: CVE Request for Drupal Contributed Modules | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| user_readonly 7.x-1.4 | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.