ZeroHour

CVE-2016-9449

CVSS 3.0
4.3 medium
EPSS
2%p79
Published
()
Modified
Description

The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.

Vendors
drupal
Products
drupal
Ecosystems
Drupal
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.