logo

CVE-2016-7570 drupal/core

Package

Manager: composer
Name: drupal/core
Vulnerable Version: >=8.0.0 <8.1.10

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00371 pctl0.58077

Details

Drupal Users without "Administer comments" can set comment visibility on nodes they can edit Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

Metadata

Created: 2022-05-17T03:47:58Z
Modified: 2024-04-23T22:37:18Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6g9h-6v79-w4pc/GHSA-6g9h-6v79-w4pc.json
CWE IDs: ["CWE-269"]
Alternative ID: GHSA-6g9h-6v79-w4pc
Finding: F159
Auto approve: 1