Drupal Subuser Module Cross Site Request Forgery and Access Security Bypass Vulnerabilities
BID:54673
Info
Drupal Subuser Module Cross Site Request Forgery and Access Security Bypass Vulnerabilities
| Bugtraq ID: | 54673 |
| Class: | Unknown |
| CVE: |
CVE-2012-4486 CVE-2012-4487 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2012 12:00AM |
| Updated: | Jan 11 2013 01:10PM |
| Credit: | Stella Power |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Subuser Module Cross Site Request Forgery and Access Security Bypass Vulnerabilities
Subuser Module for Drupal is prone to a cross-site request-forgery vulnerability and a security-bypass vulnerability.
Exploiting these issues may allow an attacker to perform certain administrative actions, bypass certain security restrictions, gain unauthorized access to the affected application, or delete certain data; Other attacks are also possible.
Subuser 6.x-1.x versions prior to 6.x-1.8 are vulnerable.
Subuser Module for Drupal is prone to a cross-site request-forgery vulnerability and a security-bypass vulnerability.
Exploiting these issues may allow an attacker to perform certain administrative actions, bypass certain security restrictions, gain unauthorized access to the affected application, or delete certain data; Other attacks are also possible.
Subuser 6.x-1.x versions prior to 6.x-1.8 are vulnerable.
Exploit / POC
Drupal Subuser Module Cross Site Request Forgery and Access Security Bypass Vulnerabilities
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into following a malicious URI.
An attacker can exploit these issues through a browser. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Drupal Subuser Module Cross Site Request Forgery and Access Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Drupal Subuser Module Cross Site Request Forgery and Access Security Bypass Vulnerabilities
References:
References:
- Drupal Homepage (Drupal)