View online: https://www.drupal.org/sa-contrib-2018-076
Project: Date Reminder [1] Date: 2018-November-28 Security risk: *Moderately critical* 10∕25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:Default [2] Vulnerability: Access bypass
Description: This module allows registered users to request email reminders to be sent at a specified time before an event.
The module doesn't sufficiently check access to nodes, allowing a user to set a reminder on a node that the user shouldn't be able to access.
This can be mitigated with configuring DateReminder with Reminder Display: "Fieldset within a node" disables the potential exploit.
Solution: Install the latest version:
* If you use the Date Reminder module for Drupal 7.x, upgrade to Date Reminder 7.x-1.15 [3]
Also see the Date Reminder [4] project page.
Reported By: * than_nak87 [5]
Fixed By: * dwillcox [6] * Balazs Janos Tatar [7] Provisional Security Team member
Coordinated By: * Balazs Janos Tatar [8] Provisional Security Team member
[1] https://www.drupal.org/project/datereminder [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/datereminder/releases/7.x-1.15 [4] https://www.drupal.org/project/datereminder [5] https://www.drupal.org/u/than_nak87 [6] https://www.drupal.org/user/230168 [7] https://www.drupal.org/user/649590 [8] https://www.drupal.org/user/649590