{"id":"DRUPAL-CONTRIB-2019-048","details":"This module enables you to use special routes for user registration with special roles and custom field sets defined for the role.\n\nThe module doesn't sufficiently check which user roles can be registered under the scenario when the user tries to register the user with the administrator role.\n\nThis vulnerability is mitigated on sites where account approval is required as the user starts as blocked but still gets the \"Administrator\" role.","modified":"2026-09-10T03:45:40.218319035Z","published":"2019-05-15T17:13:59Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2019-048"}],"affected":[{"package":{"name":"drupal/multiple_registration","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/multiple_registration?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.0"}],"database_specific":{"constraint":"\u003c2.8.0"}}],"database_specific":{"affected_versions":"\u003c2.8.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/multiple_registration/DRUPAL-CONTRIB-2019-048.json"}}],"schema_version":"1.9.0","credits":[{"name":"iswilson","contact":["https://www.drupal.org/user/415095"]}]}