View online: https://www.drupal.org/sa-contrib-2018-076 Project: Date Reminder [1] Date: 2018-November-28 Security risk: *Moderately critical* 10∕25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:Default [2] Vulnerability: Access bypass Description: This module allows registered users to request email reminders to be sent at a specified time before an event. The module doesn't sufficiently check access to nodes, allowing a user to set a reminder on a node that the user shouldn't be able to access. This can be mitigated with configuring DateReminder with Reminder Display: "Fieldset within a node" disables the potential exploit. Solution: Install the latest version: * If you use the Date Reminder module for Drupal 7.x, upgrade to Date Reminder 7.x-1.15 [3] Also see the Date Reminder [4] project page. Reported By: * than_nak87 [5] Fixed By: * dwillcox [6] * Balazs Janos Tatar [7] Provisional Security Team member Coordinated By: * Balazs Janos Tatar [8] Provisional Security Team member [1] https://www.drupal.org/project/datereminder [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/datereminder/releases/7.x-1.15 [4] https://www.drupal.org/project/datereminder [5] https://www.drupal.org/u/than_nak87 [6] https://www.drupal.org/user/230168 [7] https://www.drupal.org/user/649590 [8] https://www.drupal.org/user/649590