Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ted Bowman

#19931of 53,638
13Total CVSS
Vulnerabilities · 2
Medium
2
PT-2023-12784
6.5
2023-04-24
Drupal · Drupal · CVE-2022-25278
**Name of the Vulnerable Software and Affected Versions** Drupal (affected versions not specified) **Description** The Drupal core form API evaluates form element access incorrectly under certain circumstances. This may lead to a user being able to alter data they should not have access to. No forms provided by Drupal core are known to be vulnerable. However, forms added through contributed or custom modules or themes may be affected. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-8355
6.5
2018-03-01
Drupal · Drupal · CVE-2017-6931
**Name of the Vulnerable Software and Affected Versions** Drupal versions 8.4.x before 8.4.5 **Description** The issue allows users to update certain data without proper permissions, specifically affecting the Settings Tray module. If a Settings Tray form is implemented in a custom or contrib module, access checks should be added. This vulnerability can be mitigated by disabling the Settings Tray module. **Recommendations** For Drupal versions 8.4.x before 8.4.5, update to version 8.4.5 or later to resolve the issue. As a temporary workaround, consider disabling the Settings Tray module until the issue is resolved.