The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/10/04/6 | mailing list |
http://drupal.org/node/1700584 | patch vendor advisory |
http://drupal.org/node/1700550 | patch |
http://www.openwall.com/lists/oss-security/2012/10/07/1 | mailing list |