Release date:
Updated on:
Affected Systems:
Drupal User Read-Only Module 7.x
Drupal User Read-Only Module 6.x
Description:
--------------------------------------------------------------------------------
Drupal is an open source content management platform.
Drupal 6. The x-1.x's User Read-Only module mistakenly assigned a role when performing some operations, and can get administrator privileges after successful exploitation.
<* Source: Kellie Bradford Delaney
Link: http://secunia.com/advisories/51273/
Http://drupal.org/node/1840886
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Drupal
------
Drupal has released a Security Bulletin (1840886) and corresponding patches for this purpose:
1840886: SA-CONTRIB-2012-163-User Read-Only-Permission escalation
Link: http://drupal.org/node/1840886