The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.drupal.org/node/2582015 | mitigation vendor advisory |
http://www.securityfocus.com/bid/77023 | third party advisory vdb entry |
http://www.openwall.com/lists/oss-security/2015/10/21/2 | third party advisory mailing list |
https://www.drupal.org/node/2582283 | vendor advisory |