The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attackers to perform requests with extra privileges.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/49400 | third party advisory |
http://drupal.org/node/1618476 | patch |
http://www.osvdb.org/82727 | vdb entry |
http://www.securityfocus.com/bid/53840 | vdb entry |
http://www.openwall.com/lists/oss-security/2012/06/14/3 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/76141 | vdb entry |
http://drupal.org/node/1619808 | patch vendor advisory |