Vulnerability from drupal
Published
2019-02-06 17:36
Modified
2023-08-11 19:22
Summary
Details
This module provides a field on user profiles which allows users to get a notification when their account logs in to the site. The notification e-mail includes a link which will terminate all sessions for that user. This is useful in the case of unauthorised access to the account.
The module doesn't employ sufficient randomness in the generation of URLs, which represents an Access Bypass vulnerability.
Credits
Drew Webber
www.drupal.org/user/255969
{
"affected": [
{
"database_specific": {
"affected_versions": "\u003c1.3.0"
},
"package": {
"ecosystem": "Packagist:https://packages.drupal.org/8",
"name": "drupal/login_alert"
},
"ranges": [
{
"database_specific": {
"constraint": "\u003c1.3.0"
},
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.0"
}
],
"type": "ECOSYSTEM"
}
],
"severity": []
}
],
"aliases": [],
"credits": [
{
"contact": [
"https://www.drupal.org/user/255969"
],
"name": "Drew Webber"
}
],
"details": "This module provides a field on user profiles which allows users to get a notification when their account logs in to the site. The notification e-mail includes a link which will terminate all sessions for that user. This is useful in the case of unauthorised access to the account.\n\nThe module doesn\u0027t employ sufficient randomness in the generation of URLs, which represents an Access Bypass vulnerability.",
"id": "DRUPAL-CONTRIB-2019-013",
"modified": "2023-08-11T19:22:41.000Z",
"published": "2019-02-06T17:36:06.000Z",
"references": [
{
"type": "WEB",
"url": "https://www.drupal.org/sa-contrib-2019-013"
}
],
"schema_version": "1.7.0"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…