Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3crq-c4rc-qm8q

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

EPSS

Процентиль: 69%
0.00618
Низкий

Связанные уязвимости

nvd
около 17 лет назад

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

EPSS

Процентиль: 69%
0.00618
Низкий