Описание
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 6.38 |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE | |
wily | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
esm-apps/xenial | not-affected | |
esm-infra-legacy/trusty | not-affected | |
precise | not-affected | |
precise/esm | DNE | precise was not-affected |
trusty | not-affected | |
trusty/esm | not-affected | |
upstream | not-affected | |
vivid/stable-phone-overlay | DNE | |
vivid/ubuntu-core | DNE |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.
The Form API in Drupal 6.x before 6.38 ignores access restrictions on ...
Drupal Form API ignores access restrictions on submit buttons
EPSS
5 Medium
CVSS2
7.5 High
CVSS3