• Advisory ID: DRUPAL-SA-CONTRIB-2009-049
  • Project: Live (third-party module)
  • Version: 6.x
  • Date: 2009-July-29
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Impersonation, privilege escalation

Description

The Live module provides dynamic previews of content. When editing certain content (nodes), the current user becomes logged in as the content's original author.

Versions affected

  • Live for Drupal 6.x prior to 6.x-1.2

Drupal core is not affected. If you do not use the contributed Live module, there is nothing you need to do.

Solution

Upgrade to the latest version:

See also the Live project page.

Reported by

Roderik Muit

Fixed by

frjo

Contact

The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.