Spamicide - Critical - Access bypass - SA-CONTRIB-2020-009
Project: Spamicide
Date: 2020-April-08
Security risk: Critical 18∕25
Vulnerability: Access bypass
Description
The Spamicide module protects Drupal forms with a form field that is hidden from normal users, but visible to spam bots.
The module doesn't require appropriate permissions for administrative pages leading to an Access Bypass.
Solution
Install the latest version:
If you use the spamicide module for Drupal 7.x, upgrade to spamicide 7.x-1.3
Also see the Spamicide project page.
We value your opinion. Please add your feedback.