Vulnerability Bulletins |
SA-CORE-2014-001 - Drupal core - Multiple vulnerabilities |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2014-001Project: Drupal coreVersion: 6.x, 7.xDate: 2014-January-15Security risk: Highly criticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities were fixed in the supported Drupal core versions 6 and 7.Impersonation (OpenID module - Drupal 6 and 7 - Highly critical)A vulnerability was found in the OpenID module that allows a malicious user to log in as other users on the site, including administrators, and hijack More info: https://www.drupal.org/SA-CORE-2014-001 |
|






