Description
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2010-2389 Vulnerability (CVE-2010-2389)
WordPress Plugin Tooltipy (tooltips for WP) Multiple Vulnerabilities (5.0.2)
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-8580)
WordPress Plugin Helpie FAQ-WordPress FAQ Accordion Security Bypass (0.7)