ZeroHour

CVE-2016-7570

CVSS 3.0
4.3 medium
EPSS
2%p75
Published
()
Modified
Description

Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

Vendors
drupal
Products
drupal
Ecosystems
Drupal
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.