Date
Severity
Moderately Critical
Vulnerability
Cross Site Request Forgery
Affected versions
<7.x-2.2

Description

The Profile Module Manager module lets a low privilege role enable predefined bundles of modules on a site without granting the full administer modules permission.

The module exposes the bundle enable operation as a plain GET menu callback that carries no token, so it enables modules and, for bundles that request it, deletes the sessions of all other users purely on the strength of the request being made by a logged in user who holds the enable permission.

This vulnerability is mitigated by the fact that an attacker must convince a user who already holds the enable module bundles permission to visit a crafted page, and that the set of modules that can be turned on is limited to the bundles already present on the site.

Solution

Install the latest version.

If you use the Profile Module Manager module for Drupal 7, upgrade to Profile Module Manager 7.x-2.2:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES