Project: Role Delegation
Security risk: Moderately critical 14∕25
Vulnerability: Privilege escalation
This module allows site administrators to grant specific roles the authority to assign selected roles to users, without them needing the administer permissions permission.
The module contains an access bypass vulnerability when used in combination with the Views Bulk Operations module. An authenticated user is able to assign the administrator role to his own user.