Improper Permission Check in Subuser Module Allows Role Manipulation

Improper Permission Check in Subuser Module Allows Role Manipulation

CVE-2012-4487 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:N

The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created.

Learn more about our User Device Pen Test.