Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x42v-g6h6-346r

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.

The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.

EPSS

Процентиль: 67%
0.00548
Низкий

Связанные уязвимости

nvd
почти 12 лет назад

The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.

EPSS

Процентиль: 67%
0.00548
Низкий