Описание
The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment authors to bypass access restrictions and possibly have other unspecified impact.
Ссылки
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:a:philip_ludlam:listhandler:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00303
Низкий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
около 3 лет назад
The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment authors to bypass access restrictions and possibly have other unspecified impact.
EPSS
Процентиль: 53%
0.00303
Низкий
7.5 High
CVSS2
Дефекты
CWE-264