CVE-2016-7572
—CVSS 3.0
4.3 medium
EPSS
2%p76
Published
()
Modified
Description
The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.
- Vendors
- drupal
- Products
- drupal
- Ecosystems
- Drupal
- Weakness
- CWE-264
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.