Skip to main content

Vendor archive

boombatower CVEs

Beta · best-effort

2 CVEs tagged to vendor boombatower0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2012-4487

Published Nov 2, 2012

The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4486

Published Nov 2, 2012

Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication of arbitrary users for request…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1