CERT-In Vulnerability Note
CIVN-2015-0308
Access Bypass Vulnerability in Mollom Module of Drupal
Original Issue Date:December 14, 2015
Severity Rating: HIGH
Systems Affected
Component Affected
- Mollom 6.x-2.x versions between 6.x-2.7 through 6.x-2.14.
Overview
A vulnerability has been reported in Mollom module of Drupal which could be exploited by an attacker to bypass security restrictions to conduct further attacks.
Description
The Mollom module allows users to protect their website from spam by creating a blacklist. When the user submit some content that match with terms in the blacklist, the content is marked as spam and it is rejected as per the site configuration.
The vulnerability exists in the module due to improperly checking of access rights while accessing or modifying the blacklist for the site. An attacker may leverage this issue to bypass security restrictions and change or remove the blacklist to conduct further attacks.
Solution
Upgrade to latest version of Module Mollom 6.x-2.15
https://www.drupal.org/node/2627448
Vendor Information
Drupal
https://drupal.org/security/contrib
https://www.drupal.org/node/2627448
References
Drupal
https://drupal.org/security/contrib
https://www.drupal.org/node/2627448
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|