The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote authenticated users with the "view any quiz results" or "view results for own quiz" permission to delete arbitrary results via the delete option.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://seclists.org/oss-sec/2013/q4/210 | mailing list |
https://drupal.org/node/2123995 | patch vendor advisory |
https://drupal.org/node/2123727 | patch |