Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gh5-3hqj-x3pj

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Drupal Form API ignores access restrictions on submit buttons

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

EPSS

Процентиль: 69%
0.0062
Низкий

7.5 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

CVSS3: 7.5
nvd
больше 9 лет назад

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

CVSS3: 7.5
debian
больше 9 лет назад

The Form API in Drupal 6.x before 6.38 ignores access restrictions on ...

EPSS

Процентиль: 69%
0.0062
Низкий

7.5 High

CVSS3

Дефекты

CWE-284