The BlogAPI module does not implement correct validation for certain content fields, allowing for values to be set for fields which would otherwise be inaccessible on an internal Drupal form.
Credit:
The information has been provided by Caleb Delnay, G bor Hojtsy and Heine Deelstra.
The BlogAPI module does not implement correct validation for certain content fields, allowing for values to be set for fields which would otherwise be inaccessible on an internal Drupal form. We have hardened these checks in BlogAPI module for this release, but the security team would like to re-iterate that the 'Administer content with BlogAPI' permission should only be given to trusted users.
If the core BlogAPI module is not enabled, your site will not be affected.
This bug affects both Drupal 5.x and Drupal 6.x.
Vendor Status:
Drupal issued an update for this vulnerability