Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-5557

Опубликовано: 03 дек. 2012
Источник: nvd
CVSS2: 3.6
EPSS Низкий

Описание

The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain operations, as demonstrated by changing a password.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:user_read-only_project:user_readonly:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:6.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:6.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:6.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:6.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:7.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:7.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:7.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:7.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:user_read-only_project:user_readonly:7.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00171
Низкий

3.6 Low

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
около 3 лет назад

The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain operations, as demonstrated by changing a password.

EPSS

Процентиль: 39%
0.00171
Низкий

3.6 Low

CVSS2

Дефекты

CWE-264