Description
Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-0500 Vulnerability (CVE-2015-0500)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-43946)
WordPress Plugin Ajax Calendar 'example.php' Cross-Site Scripting (1.0)
WordPress Plugin Editorial Calendar Multiple Vulnerabilities (2.6)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7831)