Drupal Mime Mail Module File Attachments Access Bypass Vulnerability
BID:65996
Info
Drupal Mime Mail Module File Attachments Access Bypass Vulnerability
| Bugtraq ID: | 65996 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2014 12:00AM |
| Updated: | Mar 05 2014 12:00AM |
| Credit: | Heine Deelstra of the Drupal Security Team |
| Vulnerable: |
Drupal Mime Mail 7.x-1.0-beta2 Drupal Mime Mail 6.X-1.3 |
| Not Vulnerable: |
Drupal Mime Mail 7.x-1.0-beta3 Drupal Mime Mail 6.X-1.4 |
Discussion
Drupal Mime Mail Module File Attachments Access Bypass Vulnerability
The Mime Mail module for Drupal is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
The following versions are vulnerable:
Mime Mail 6.x-1.x versions prior to 6.x-1.4.
Mime Mail 7.x-1.x versions prior to 7.x-1.0-beta3.
The Mime Mail module for Drupal is prone to an access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
The following versions are vulnerable:
Mime Mail 6.x-1.x versions prior to 6.x-1.4.
Mime Mail 7.x-1.x versions prior to 7.x-1.0-beta3.
Exploit / POC
Drupal Mime Mail Module File Attachments Access Bypass Vulnerability
An attacker can exploit this issue readily available tools and browser.
An attacker can exploit this issue readily available tools and browser.
Solution / Fix
Drupal Mime Mail Module File Attachments Access Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Drupal Mime Mail Module File Attachments Access Bypass Vulnerability
References:
References:
- Mime Mail Homepage (Drupal)
- SA-CONTRIB-2014-029 - Mime Mail - Access Bypass (Drupal)