• Advisory ID: DRUPAL-SA-2008-043
  • Project: Outline designer (third-party module)
  • Version: 5.x
  • Date: 2008-July-2
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Privilege escalation

Description

The Outline designer module provides a visual way of structuring content in books.

A programming error in the module causes the current user to become authenticated as the author of the viewed content item.

Versions affected

  • Outline designer for Drupal 5.x prior to 5.x-1.4.

Drupal core is not affected. If you do not use the contributed Outline designer module, there is nothing you need to do.

Solution

Install the latest version:

See also the Outline designer project page.

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact and by selecting the security issues category.