ZeroHour

CVE-2016-7572

CVSS 3.0
4.3 medium
EPSS
2%p76
Published
()
Modified
Description

The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

Vendors
drupal
Products
drupal
Ecosystems
Drupal
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.