[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.4] drupal7: Multiple Vulnerabilities (no CVE)

ID: oval:org.secpod.oval:def:1800016Date: (C)2018-03-29   (M)2021-11-09
Class: PATCHFamily: unix




CVE ID: not yet available Saving user accounts can sometimes grant the user all roles. A vulnerability exists in the User module, where if some specific contributed or custom code triggers a rebuild of the user profile form, a registered user can be granted all user roles on the site. This would typically result in the user gaining administrative access. This issue is mitigated by the fact that it requires contributed or custom code that performs a form rebuild during submission of the user profile form. Views can allow unauthorized users to see Statistics information. An access bypass vulnerability exists in the Views module, where users without the "View content count" permission can see the number of hits collected by the Statistics module for results in the view. Affected versions: Drupal core 7.x versions prior to 7.44 Drupal core 8.x versions prior to 8.1.3 Solution. If you use Drupal 7.x, upgrade to Drupal core 7.44 If you use Drupal 8.x, upgrade to Drupal core 8.1.3 Reference:

Platform:
Alpine Linux 3.4
Product:
drupal7
Reference:
5746
CPE    2
cpe:/a:apache:subversion
cpe:/o:alpinelinux:alpine_linux:3.4

© SecPod Technologies