The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the database.
Software | From | Fixed in |
---|---|---|
site_documentation_project / site_documentation | 5.x-1.0 | 5.x-1.8 |
site_documentation_project / site_documentation | 6.x-1.0 | 6.x-1.1 |