Beveiligingsadvies

CVE-2016-3169

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-04-12 15:00:00
Laatst bijgewerkt 2024-08-05 23:47:57
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.