Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqxc-cppg-4xp8

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

Drupal Reflected file download vulnerability

The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."

Пакеты

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

Наименование

drupal/core

composer
Затронутые версииВерсия исправления

>= 7.0, < 7.43

7.43

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 7.0, < 7.43

7.43

Наименование

drupal/drupal

composer
Затронутые версииВерсия исправления

>= 6.0, < 6.38

6.38

EPSS

Процентиль: 73%
0.00791
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
около 9 лет назад

The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."

CVSS3: 6.4
nvd
около 9 лет назад

The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."

CVSS3: 6.4
debian
около 9 лет назад

The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might ...

EPSS

Процентиль: 73%
0.00791
Низкий

6.4 Medium

CVSS3