CVE-2008-4792: Medium severity drupal vulnerability
Published Oct 29, 2008
·Updated
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
Affected Software
2 affected components
Drupal Drupal>=5.0<5.11
Drupal Drupal>=6.0<6.5
Remediation
Patch Available
Event History
Oct 29, 2008
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4792?
CVE-2008-4792 is considered a medium severity vulnerability due to its potential to allow authenticated users to bypass access restrictions.
2
How do I fix CVE-2008-4792?
To fix CVE-2008-4792, update your Drupal installation to version 5.11 or 6.5 or later.
3
What versions of Drupal are affected by CVE-2008-4792?
CVE-2008-4792 affects Drupal version 5.x before 5.11 and 6.x before 6.5.
4
What types of users are impacted by CVE-2008-4792?
Remote authenticated users can exploit CVE-2008-4792 to bypass intended access restrictions.
5
What is the nature of the flaw in CVE-2008-4792?
CVE-2008-4792 involves improper validation of content fields in an internal Drupal form.