Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ted Bowman

#20031de 53,639
13CVSS total
Vulnerabilidades · 2
Média
2
PT-2023-12784
6.5
2023-04-24
Drupal · Drupal · CVE-2022-25278
**Name of the Vulnerable Software and Affected Versions** Drupal (affected versions not specified) **Description** The Drupal core form API evaluates form element access incorrectly under certain circumstances. This may lead to a user being able to alter data they should not have access to. No forms provided by Drupal core are known to be vulnerable. However, forms added through contributed or custom modules or themes may be affected. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-8355
6.5
2018-03-01
Drupal · Drupal · CVE-2017-6931
**Name of the Vulnerable Software and Affected Versions** Drupal versions 8.4.x before 8.4.5 **Description** The issue allows users to update certain data without proper permissions, specifically affecting the Settings Tray module. If a Settings Tray form is implemented in a custom or contrib module, access checks should be added. This vulnerability can be mitigated by disabling the Settings Tray module. **Recommendations** For Drupal versions 8.4.x before 8.4.5, update to version 8.4.5 or later to resolve the issue. As a temporary workaround, consider disabling the Settings Tray module until the issue is resolved.