Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/37123 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53896 | vdb entry |
http://www.securityfocus.com/bid/36786 | vdb entry patch |
http://drupal.org/node/610828 | patch vendor advisory |
http://osvdb.org/59124 | vdb entry |
http://www.vupen.com/english/advisories/2009/2998 | vdb entry patch vendor advisory |
http://drupal.org/node/610818 | patch vendor advisory |