Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an error in how the permissions were assembled that assigns extra permissions to users.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Yazd_discussion_forum | Yazd | 1.0 (including) | 1.0 (including) |
Yazd_discussion_forum | Yazd | 2.0 (including) | 2.0 (including) |
Yazd_discussion_forum | Yazd | 2.1 (including) | 2.1 (including) |
Yazd_discussion_forum | Yazd | 2.2 (including) | 2.2 (including) |
Yazd_discussion_forum | Yazd | 2.3 (including) | 2.3 (including) |
Yazd_discussion_forum | Yazd | 2.4 (including) | 2.4 (including) |