Drupal Monster Menus Module Access Bypass Vulnerability
BID:61711
Info
Drupal Monster Menus Module Access Bypass Vulnerability
| Bugtraq ID: | 61711 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-4230 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2013 12:00AM |
| Updated: | Aug 07 2013 12:00AM |
| Credit: | Five Colleges, Inc. and Jay Dansand |
| Vulnerable: |
Drupal monster_menus 7.x-1.12 Drupal monster_menus 7.x-1.11 Drupal monster_menus 7.x-1.0 Drupal monster_menus 6.x-6.60 Drupal monster_menus 6.x-6.19 |
| Not Vulnerable: |
Drupal monster_menus 7.x-1.13 Drupal monster_menus 6.x-6.61 |
Discussion
Drupal Monster Menus Module Access Bypass Vulnerability
The Monster Menus module for Drupal is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Monster Menus 6.x-6.x versions prior to 6.x-6.61 and 7.x-1.x versions prior to 7.x-1.13 are vulnerable.
The Monster Menus module for Drupal is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Monster Menus 6.x-6.x versions prior to 6.x-6.61 and 7.x-1.x versions prior to 7.x-1.13 are vulnerable.
Solution / Fix
Drupal Monster Menus Module Access Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.