ZeroHour

CVE-2016-3169

CVSS 3.0
8.1 high
EPSS
2%p82
Published
()
Modified
Description

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.

Vendors
debiandrupal
Products
debian linux, drupal
Ecosystems
Drupal
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.