VWE-2011-0148 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2011-0148
This page is a chapter in Info Known Vulnerabilities

This page has been seen 407,331 times.

    • Created by on
      Last updated by on
Common NameSocial Escalation Vulnerability
VWE-IDVWE-2011-0148
Related Report#2546
SeverityExtreme
Exploit DifficultyEASY
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionPermissions escalation. Does not affect Lite versions.
DiscoveredNovember 28, 2011
ResolvedDecember 10, 2011
Patches Available3.0.16
3.0.15 Patch Level 1
3.0.14 Patch Level 1
3.0.13 Patch Level 1
3.0.12 Patch Level 1
3.0.11 Patch Level 2
3.0.10 Patch Level 2
3.0.9 Patch Level 2
WorkaroundDo not set Social Group Mask to the administrator group, moderator group, banned group, or guest group. It is very easy to set to the administrator group accidentally.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.