First published: Wed Oct 29 2008(Updated: )
The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | >=5.0<5.11 | |
Drupal Drupal | >=6.0<6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4791 is classified as a medium severity vulnerability, allowing potential unauthorized access.
To fix CVE-2008-4791, upgrade your Drupal installation to at least version 5.11 for Drupal 5.x or 6.5 for Drupal 6.x.
CVE-2008-4791 affects users of Drupal versions 5.x prior to 5.11 and 6.x prior to 6.5.
CVE-2008-4791 can allow remote authenticated users to bypass login restrictions, potentially compromising user accounts.
CVE-2008-4791 is not a remote code execution vulnerability but rather allows unauthorized login access.