Drupal Webform CiviCRM Integration Module Access Bypass Vulnerability
BID:56444
Info
Drupal Webform CiviCRM Integration Module Access Bypass Vulnerability
| Bugtraq ID: | 56444 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2012 12:00AM |
| Updated: | Nov 07 2012 12:00AM |
| Credit: | Coleman Watts |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Drupal Webform CiviCRM Integration Module Access Bypass Vulnerability
The Webform CiviCRM Integration module for Drupal is prone to an access-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to sensitive areas of the application to perform unauthorized actions; this may aid in launching further attacks.
Webform CiviCRM Integration 7.x-3.0 versions prior to 7.x-3.4 are vulnerable.
The Webform CiviCRM Integration module for Drupal is prone to an access-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to sensitive areas of the application to perform unauthorized actions; this may aid in launching further attacks.
Webform CiviCRM Integration 7.x-3.0 versions prior to 7.x-3.4 are vulnerable.
Exploit / POC
Drupal Webform CiviCRM Integration Module Access Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Webform CiviCRM Integration Module Access Bypass Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.