CERT-In Vulnerability Note
CIVN-2022-0470
Access Bypass Vulnerability in Entity Registration Module of Drupal
Original Issue Date:December 12, 2022
Severity Rating: MEDIUM
Software Affected
- Entity Registration module version prior 7.1.9
Overview
A vulnerability has been reported in Entity registration module of Drupal which could allow an attacker to bypass security restrictions on targeted system.
Description
This vulnerability exists in the Entity registration module due to insufficient restrict update access. An attacker could exploit this vulnerability with "update own [registration type]" permission to gain unauthorized access.
Successful exploitation of this vulnerability could allow an attacker to bypass and manage security restrictions.
Solution
Apply appropriate upgrade as mentioned:
https://www.drupal.org/project/registration/releases/7.x-1.9
Vendor Information
Drupal
https://www.drupal.org/sa-contrib-2022-063
References
Drupal
https://www.drupal.org/sa-contrib-2022-063
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|