The BOTCHA Spam Prevention module 7.x-1.x before 7.x-1.6, 7.x-2.x before 7.x-2.1, and 7.x-3.x before 7.x-3.3 for Drupal, when the debugging level is set to 5 or 6, logs the content of submitted forms, which allows context-dependent users to obtain sensitive information such as usernames and passwords by reading the log file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://drupal.org/node/2064785 | patch |
http://www.openwall.com/lists/oss-security/2013/08/22/2 | mailing list |
https://drupal.org/node/2064783 | |
https://drupal.org/node/2065057 | vendor advisory |
https://drupal.org/node/2064781 | patch |