We found results for “”
WS-2018-0195
Good to know:
Date: January 20, 2018
Drupal core versions 7.x until 7.60, 8.5.x until 8.5.8, 8.6.x until 8.6.2, vulnerable to access bypass due to an issue to check users access for certain transitions.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Access Control
CWE-284Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |