Drupal contains a flaw that may lead to an unauthorized information disclosure. The issue is due to search results improperly displaying blocked users in search results. This may allow an unprivileged remote attacker to gain access to potentially sensitive information.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related,
Concern
Solution
It has been reported that this issue has been fixed. Upgrade to version 6.27, 7.18, or higher, to address this vulnerability.