[Security-news] SA-CONTRIB-2009-026 - LoginToboggan - Access bypass

security-news at drupal.org security-news at drupal.org
Wed May 13 16:54:57 UTC 2009


  * Advisory ID: DRUPAL-SA-CONTRIB-2009-026
  * Project: LoginToboggan (third-party module)
  * Version: 6.x
  * Date: 2009-May-13
  * Security risk: Moderately critical
  * Exploitable from: Remote
  * Vulnerability: Access bypass

-------- DESCRIPTION  
---------------------------------------------------------

LoginToboggan includes a setting which, if enabled, allows users to log in
using either their username or e-mail address. In some circumstances,
previously blocked users may still be able to access the site if this setting
is enabled.
-------- VERSIONS AFFECTED  
---------------------------------------------------

  * LoginToboggan 6.x-1.x prior to 6.x-1.5

LoginToboggan for Drupal 5.x is not affected by this vulnerability. Drupal
core is not affected. If you do not use the contributed LoginToboggan module,
there is nothing you need to do.
-------- SOLUTION  
------------------------------------------------------------

Upgrade to the latest version:
  * If you use LoginToboggan 6.x-1.x upgrade to LoginToboggan 6.x-1.5 [1]

As a temporary workaround, you may also disable the 'Allow users to login
using their e-mail address' setting at Administer -> User management ->
LoginToboggan. See also the LoginToboggan project page [2].
-------- REPORTED BY  
---------------------------------------------------------

Chad Phillips [3] of the Drupal Security Team [4].
-------- FIXED BY  
------------------------------------------------------------

Chad Phillips [5] of the Drupal Security Team [6].
-------- CONTACT  
-------------------------------------------------------------

The security contact for Drupal can be reached at security at drupal.org or
via the form at http://drupal.org/contact.

[1] http://drupal.org//drupal.org/node/461682
[2] http://drupal.org/project/logintoboggan
[3] http://drupal.org/user/22079
[4] http://drupal.org/security-team
[5] http://drupal.org/user/22079
[6] http://drupal.org/security-team



More information about the Security-news mailing list