SB2024052313 - Improper access control in Email Contact module for Drupal



SB2024052313 - Improper access control in Email Contact module for Drupal

Published: May 23, 2024

Security Bulletin ID SB2024052313
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: N/A)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected module does not sufficiently handle restricted entity or field access to the mail sending form, when the "Email contact link" formatter is used. A remote attacker can bypass implemented security restrictions and gain unauthorized access to sensitvie information.


Remediation

Install update from vendor's website.