CVE-2016-7570 – drupal/core
Package
Manager: composer
Name: drupal/core
Vulnerable Version: >=8.0.0 <8.1.10
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00371 pctl0.58077
Details
Drupal Users without "Administer comments" can set comment visibility on nodes they can edit Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.
Metadata
Created: 2022-05-17T03:47:58Z
Modified: 2024-04-23T22:37:18Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6g9h-6v79-w4pc/GHSA-6g9h-6v79-w4pc.json
CWE IDs: ["CWE-269"]
Alternative ID: GHSA-6g9h-6v79-w4pc
Finding: F159
Auto approve: 1