Drupal CKEditor Module CVE-2011-4972 Access Bypass Vulnerability
BID:60326
Info
Drupal CKEditor Module CVE-2011-4972 Access Bypass Vulnerability
| Bugtraq ID: | 60326 |
| Class: | Access Validation Error |
| CVE: |
CVE-2011-4972 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2011 12:00AM |
| Updated: | Nov 09 2011 12:00AM |
| Credit: | Joel Walters |
| Vulnerable: |
Drupal CKEditor 7.x-1.4 |
| Not Vulnerable: |
Drupal CKEditor 7.x-1.5 |
Discussion
Drupal CKEditor Module CVE-2011-4972 Access Bypass Vulnerability
The CKEditor module for Drupal is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
CKEditor 7.x-1.4 is vulnerable; other versions may also be affected.
The CKEditor module for Drupal is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
CKEditor 7.x-1.4 is vulnerable; other versions may also be affected.
Solution / Fix
Drupal CKEditor Module CVE-2011-4972 Access Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Drupal CKEditor 7.x-1.4
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Drupal CKEditor 7.x-1.4
-
Drupal ckeditor 7.x-1.5
https://drupal.org/node/1336272
References
Drupal CKEditor Module CVE-2011-4972 Access Bypass Vulnerability
References:
References:
- Drupal Language Switcher Dropdown Homepage (Drupal)
- Drupal CKEditor Homepage (Drupal)
- SA-CONTRIB-2011-054 - CKEditor - Access bypass (Drupal)