Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3162

Опубликовано: 12 апр. 2016
Источник: debian
EPSS Низкий

Описание

The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal8itppackage
drupal7fixed7.43-1package
drupal6not-affectedpackage

Примечания

  • https://www.drupal.org/SA-CORE-2016-001

  • https://www.openwall.com/lists/oss-security/2016/02/24/19

EPSS

Процентиль: 38%
0.00163
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 9 лет назад

The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.

CVSS3: 8.1
nvd
около 9 лет назад

The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.

CVSS3: 8.1
github
около 3 лет назад

Drupal File upload access bypass and denial of service

EPSS

Процентиль: 38%
0.00163
Низкий