The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote attackers to edit an arbitrary users questions and answers via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_questions | Security_questions_project | 6.x-1.0 (including) | 6.x-1.0 (including) |
Security_questions | Security_questions_project | 6.x-1.x-dev (including) | 6.x-1.x-dev (including) |
Security_questions | Security_questions_project | 7.x-1.0 (including) | 7.x-1.0 (including) |
Security_questions | Security_questions_project | 7.x-1.x-dev (including) | 7.x-1.x-dev (including) |