The module supports unpublishing comments by privileged users. Users with the “post comments without approval” permission however could craft a URL which allowed them to republish previously unpublished comments.
Part of security release SA-CORE-2010-002
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6
- Drupal 6.7
- Drupal 6.8
- Drupal 6.9
- Drupal 6.10
- Drupal 6.11
- Drupal 6.12
- Drupal 6.13
- Drupal 6.14
- Drupal 6.15
- Drupal 6.16
- Drupal 6.17