Description
The Instagram Social feed module pulls photos from Instagram accounts and hashtags and displays them on the site after an administrator approves each item.
The module registers an approval callback that toggles the publication status of a photo but leaves the route open to every visitor and does not verify a request token, so any anonymous user can change which photos are published by sending a single crafted request.
This vulnerability is mitigated by the fact that an attacker must know a valid Instagram media identifier to target, and the impact is limited to changing the publication status of imported photos rather than reading or destroying data.
Solution
Install the latest version.
If you use the Instagram Social feed module for Drupal 7, upgrade to Instagram Social feed 7.x-1.6:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES