Description

This module enables you to quickly toggle various user, node and field related settings via ajax links.

The recent 7.x-1.3 and 1.4 releases of the module include a rewrite of the access control which doesn't correctly implement support for the user status (allow/block) link.

This vulnerability is mitigated by the fact that the administrator must enable the link in the fasttoggle configuration and allow user profiles to be viewed by anonymous or logged in users. For user 1 to be affected, the administrator must also enable the fasttoggle setting that allows that account to be blocked via fasttoggle.

All uses of the Fasttoggle module are logged, so any invocations of the exploit will be recorded. Accounts can only be blocked or unblocked via the exploit.

CVE identifier(s) issued

  • CVE-2014-5268

Versions affected

Drupal core is not affected. If you do not use the contributed Fasttoggle module,
there is nothing you need to do.

Solution

Install the latest version:

Also see the Fasttoggle project page.

Reported by

Fixed by

Coordinated by

Contact and More Information

The Drupal security team can be reached at security at drupal.org or via the contact form at href="http://drupal.org/contact">http://drupal.org/contact.

Learn more about the Drupal Security team and their policies, href="http://drupal.org/writing-secure-code">writing secure code for Drupal, and href="http://drupal.org/security/secure-configuration">securing your site.