Drupal Notify Module Security Bypass Vulnerability
BID:33282
Info
Drupal Notify Module Security Bypass Vulnerability
| Bugtraq ID: | 33282 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2009 12:00AM |
| Updated: | Jan 16 2009 11:22PM |
| Credit: | Philippe Jadin and Bill Kennedy |
| Vulnerable: |
Drupal Notify 5.x-1.1 |
| Not Vulnerable: |
Drupal Notify 5.x-1.2 |
Discussion
Drupal Notify Module Security Bypass Vulnerability
The Notify module for Drupal is affected by a security-bypass vulnerability.
Successful attacks may allow an attacker to log in as another user and potentially gain elevated privileges.
Versions prior to Notify 5.x-1.2 are affected.
The Notify module for Drupal is affected by a security-bypass vulnerability.
Successful attacks may allow an attacker to log in as another user and potentially gain elevated privileges.
Versions prior to Notify 5.x-1.2 are affected.
Exploit / POC
Drupal Notify Module Security Bypass Vulnerability
An attacker can carry out this attack via a browser.
An attacker can carry out this attack via a browser.
Solution / Fix
Drupal Notify Module Security Bypass Vulnerability
Solution:
The vendor released Notify 5.x-1.2 to address this issue. Please see the references for more information.
Drupal Notify 5.x-1.1
Solution:
The vendor released Notify 5.x-1.2 to address this issue. Please see the references for more information.
Drupal Notify 5.x-1.1
-
Drupal notify-5.x-1.2.tar.gz
http://ftp.drupal.org/files/projects/notify-5.x-1.2.tar.gz
References
Drupal Notify Module Security Bypass Vulnerability
References:
References:
- Notify (Drupal)
- SA-CONTRIB-2009-004 - Notify - Privilege escalation (Drupal)