Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p7x-pg2q-x6w8

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.

The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.

EPSS

Процентиль: 54%
0.00318
Низкий

9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9
nvd
около 10 лет назад

The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.

EPSS

Процентиль: 54%
0.00318
Низкий

9 Critical

CVSS3

Дефекты

CWE-94