First published: Wed Oct 29 2008(Updated: )
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | >=5.0<5.11 | |
Drupal Drupal | >=6.0<6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4792 is considered a medium severity vulnerability due to its potential to allow authenticated users to bypass access restrictions.
To fix CVE-2008-4792, update your Drupal installation to version 5.11 or 6.5 or later.
CVE-2008-4792 affects Drupal version 5.x before 5.11 and 6.x before 6.5.
Remote authenticated users can exploit CVE-2008-4792 to bypass intended access restrictions.
CVE-2008-4792 involves improper validation of content fields in an internal Drupal form.