CVE-2012-4487
Published Nov 2, 2012The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching…
Vendor archive
2 CVEs tagged to vendor boombatower — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching…
Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication of arbitrary users for request…