Drupal Banckle Chat module Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
Drupal Banckle Chat
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-0318
Drupal is an open-source content management platform.
The management page of The Drupal Banckle Chat module does not properly restrict access, allowing remote attackers to bypass security restrictions.
<* Source: Kurt Seifried (kurt@seifried.org)
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2013-0318
Http://www.openwall.com/lists/oss-security/2013/02/21/5
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Drupal
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://drupal.org/node/