7.5
CVSSv2

CVE-2014-1475

Published: 24/01/2014 Updated: 21/02/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The OpenID module in Drupal 6.x prior to 6.30 and 7.x prior to 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 7.0

drupal drupal 7.1

drupal drupal 7.10

drupal drupal 7.18

drupal drupal 7.19

drupal drupal 7.13

drupal drupal 7.14

drupal drupal 7.21

drupal drupal 7.22

drupal drupal 7.11

drupal drupal 7.12

drupal drupal 7.2

drupal drupal 7.20

drupal drupal 7.15

drupal drupal 7.16

drupal drupal 7.17

drupal drupal 7.23

drupal drupal 7.24

drupal drupal 6.0

drupal drupal 6.11

drupal drupal 6.12

drupal drupal 6.19

drupal drupal 6.2

drupal drupal 6.26

drupal drupal 6.27

drupal drupal 6.15

drupal drupal 6.16

drupal drupal 6.22

drupal drupal 6.23

drupal drupal 6.13

drupal drupal 6.14

drupal drupal 6.20

drupal drupal 6.21

drupal drupal 6.28

drupal drupal 6.1

drupal drupal 6.10

drupal drupal 6.17

drupal drupal 6.18

drupal drupal 6.24

drupal drupal 6.25

Vendor Advisories

Christian Mainka and Vladislav Mladenov reported a vulnerability in the OpenID module of Drupal, a fully-featured content management framework A malicious user could exploit this flaw to log in as other users on the site, including administrators, and hijack their accounts These fixes require extra updates to the database which can be done from t ...