PT-2008-3270 · Drupal · Drupal
Publicado
2008-04-11
·
Atualizado
2021-04-19
·
CVE-2008-1729
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions prior to 6.2
Description
The issue affects the menu system, allowing remote attackers to edit profile pages of arbitrary users and obtain sensitive information from tracker and blog pages due to a missing check for the
access content permission. Additionally, remote authenticated users with administration page view access can edit content types.Recommendations
For versions prior to 6.2, update to version 6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to administration pages and sensitive user information until the update can be applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Drupal