CVE-2019-10911
- EPSS 0.31%
- Published 16.05.2019 22:29:00
- Last modified 21.11.2024 04:20:07
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functional...
CVE-2019-11831
- EPSS 7.36%
- Published 09.05.2019 04:29:01
- Last modified 21.11.2024 04:21:50
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/b...
CVE-2019-11358
- EPSS 2.4%
- Published 20.04.2019 00:29:00
- Last modified 21.11.2024 04:20:56
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the n...
CVE-2019-6341
- EPSS 54.56%
- Published 26.03.2019 18:29:01
- Last modified 21.11.2024 04:46:26
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) ...
CVE-2019-6340
- EPSS 94.44%
- Published 21.02.2019 21:29:00
- Last modified 07.02.2025 14:55:30
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following co...
CVE-2017-6922
- EPSS 0.85%
- Published 22.01.2019 15:29:00
- Last modified 21.11.2024 03:30:49
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rathe...
CVE-2017-6923
- EPSS 0.26%
- Published 22.01.2019 15:29:00
- Last modified 21.11.2024 03:30:49
In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is m...
CVE-2019-6339
- EPSS 80.96%
- Published 22.01.2019 15:29:00
- Last modified 21.11.2024 04:46:26
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code...
- EPSS 1.11%
- Published 22.01.2019 14:29:00
- Last modified 21.11.2024 04:46:26
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-20...
CVE-2017-6921
- EPSS 0.38%
- Published 15.01.2019 21:29:00
- Last modified 21.11.2024 03:30:48
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is enabled and a...