• Advisory ID: SA-CONTRIB-2011-031
  • Project: SunMailer Newsletter (third-party module)
  • Version: 6.x
  • Date: 2011-July-20
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

SunMailer Newsletter creates an email newsletter that users can subscribe to. The module includes a page where authenticated users can view and/or edit their newsletter subscription. Access to this page was accidentally granted to anonymous users, creating an access bypass that disclosed all user's newsletter subscription to anonymous users and also allowed anonymous users to tamper with the newsletter subscription.

This vulnerability is mitigated by the fact that it does not disclose the email address of the subscriber. The exploit is also accessible only by directly accessing the URL leading to the user's subscription page; no link to the vulnerable page is shown in the user interface.

Versions affected

  • 6.x-1.6 or prior versions

Drupal core is not affected. If you do not use the contributed SunMailer Newsletter module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the SunMailer Newsletter module for Drupal 6.x, upgrade to version 6.x-1.7

See also the SunMailer Newsletter project page.

Reported by

Fixed by

Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.