Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Metadot_portal_server | Metadot | 5.5.2.1 (including) | 5.5.2.1 (including) |
Metadot_portal_server | Metadot | 5.6.4 (including) | 5.6.4 (including) |
Metadot_portal_server | Metadot | 5.6.4.1 (including) | 5.6.4.1 (including) |
Metadot_portal_server | Metadot | 5.6.4.2 (including) | 5.6.4.2 (including) |
Metadot_portal_server | Metadot | 5.6.4.3 (including) | 5.6.4.3 (including) |
Metadot_portal_server | Metadot | 5.6.5 (including) | 5.6.5 (including) |
Metadot_portal_server | Metadot | 5.6.5.1 (including) | 5.6.5.1 (including) |
Metadot_portal_server | Metadot | 5.6.5.2 (including) | 5.6.5.2 (including) |
Metadot_portal_server | Metadot | 5.6.5.3 (including) | 5.6.5.3 (including) |
Metadot_portal_server | Metadot | 5.6.5.3.1 (including) | 5.6.5.3.1 (including) |
Metadot_portal_server | Metadot | 5.6.5.4b5 (including) | 5.6.5.4b5 (including) |
Metadot_portal_server | Metadot | 5.6.6 (including) | 5.6.6 (including) |
Metadot_portal_server | Metadot | 6.4 (including) | 6.4 (including) |
Metadot_portal_server | Metadot | 6.4.1 (including) | 6.4.1 (including) |
Metadot_portal_server | Metadot | 6.4.2 (including) | 6.4.2 (including) |
Metadot_portal_server | Metadot | 6.4.3 (including) | 6.4.3 (including) |
Metadot_portal_server | Metadot | 6.4.4 (including) | 6.4.4 (including) |