SB2016091916 - Access rules bypass in Drupal Drupal



SB2016091916 - Access rules bypass in Drupal Drupal

Published: September 19, 2016

Security Bulletin ID SB2016091916
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Access rules bypass (CVE-ID: N/A)

The vulnerability allows users to log in the site if they weren't allowed to do it before.
The weakness exists due to deficiency in the user module that exposes forbidden users ability to log into the site.
Successful exploitation of the vulnerablity results in successful logging into the site by the blocked user.

Remediation

Install update from vendor's website.