Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gh5-3hqj-x3pj

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Drupal Form API ignores access restrictions on submit buttons

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

EPSS

Процентиль: 69%
0.00607
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

CVSS3: 7.5
nvd
около 9 лет назад

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

CVSS3: 7.5
debian
около 9 лет назад

The Form API in Drupal 6.x before 6.38 ignores access restrictions on ...

EPSS

Процентиль: 69%
0.00607
Низкий

7.5 High

CVSS3

Дефекты

CWE-284