CVE-2010-3093: Low severity drupal vulnerability
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3093?
CVE-2010-3093 is classified as a moderate severity vulnerability which allows authenticated users to bypass comment access restrictions.
How do I fix CVE-2010-3093?
To fix CVE-2010-3093, update your Drupal installation to version 5.23 or 6.18 or later.
Who is affected by CVE-2010-3093?
CVE-2010-3093 affects Drupal versions 5.x before 5.23 and 6.x before 6.18.
What type of attack does CVE-2010-3093 enable?
CVE-2010-3093 enables a privilege escalation attack allowing users to reinstate removed comments via a crafted URL.
Is CVE-2010-3093 a local or remote vulnerability?
CVE-2010-3093 is a remote vulnerability that requires authenticated user access to exploit.