ZeroHour

CVE-2017-6377

CVSS 3.0
7.5 high
EPSS
2%p78
Published
()
Modified
Description

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

Vendors
drupal
Products
drupal
Ecosystems
Drupal
Weakness
CWE-863
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news