Drupal SA-CONTRIB-2019-059 Access Bypass Vulnerability
BID:109372
Info
Drupal SA-CONTRIB-2019-059 Access Bypass Vulnerability
| Bugtraq ID: | 109372 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2019 12:00AM |
| Updated: | Jul 24 2019 12:00AM |
| Credit: | Marcelo Vani |
| Vulnerable: |
Drupal Facebook Messenger Customer Chat Plugin 7.x-1.x-dev Drupal Facebook Messenger Customer Chat Plugin 7.x-1.0 |
| Not Vulnerable: |
Drupal Facebook Messenger Customer Chat Plugin 7.x-1.1 |
Discussion
Drupal SA-CONTRIB-2019-059 Access Bypass Vulnerability
The Facebook Messenger Customer Chat Plugin module for Drupal is prone to an access-bypass vulnerability.
Attackers can leverage this issue to bypass security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Facebook Messenger Customer Chat Plugin module 7.x versions prior to 7.x-1.1 are vulnerable.
The Facebook Messenger Customer Chat Plugin module for Drupal is prone to an access-bypass vulnerability.
Attackers can leverage this issue to bypass security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Facebook Messenger Customer Chat Plugin module 7.x versions prior to 7.x-1.1 are vulnerable.
Exploit / POC
Drupal SA-CONTRIB-2019-059 Access Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Drupal SA-CONTRIB-2019-059 Access Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Drupal SA-CONTRIB-2019-059 Access Bypass Vulnerability
References:
References: