SB2016091916 - Access rules bypass in Drupal Drupal
Published: September 19, 2016
Security Bulletin ID
SB2016091916
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Access rules bypass (CVE-ID: N/A)
The vulnerability allows users to log in the site if they weren't allowed to do it before.The weakness exists due to deficiency in the user module that exposes forbidden users ability to log into the site.
Successful exploitation of the vulnerablity results in successful logging into the site by the blocked user.
Remediation
Install update from vendor's website.