An issue was discovered in the Masquerade module before 1...
High severity
Unreviewed
Published
Mar 8, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Mar 7, 2025
Published to the GitHub Advisory Database
Mar 8, 2025
An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. The module provides a "Masquerade as admin" permission to restrict people (who can masquerade) from switching to an account with administrative privileges. This permission is not always honored and may allow non-administrative users to masquerade as an administrator. This vulnerability is mitigated by the fact that an attacker must have a role with the "Masquerade as user" permission.
References