The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the nodes author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Feeds | Feeds_project | 7.x-2.0-alpha1 (including) | 7.x-2.0-alpha1 (including) |
Feeds | Feeds_project | 7.x-2.0-alpha2 (including) | 7.x-2.0-alpha2 (including) |
Feeds | Feeds_project | 7.x-2.0-alpha3 (including) | 7.x-2.0-alpha3 (including) |
Feeds | Feeds_project | 7.x-2.0-alpha4 (including) | 7.x-2.0-alpha4 (including) |
Feeds | Feeds_project | 7.x-2.0-alpha5 (including) | 7.x-2.0-alpha5 (including) |
Feeds | Feeds_project | 7.x-2.x (including) | 7.x-2.x (including) |