CVE-2012-4498 Information

Description

The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the \Campaign\ content type which might allow remote attackers to bypass access restrictions and possibly have other unspecified impact.

Reference

http://drupal.org/node/1762152 http://drupal.org/node/1762160 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1

Share on: