Drupal

Drupal

271 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 13.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

  • EPSS 0.69%
  • Veröffentlicht 13.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

  • EPSS 0.07%
  • Veröffentlicht 13.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.

  • EPSS 0.6%
  • Veröffentlicht 20.04.2017 02:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.

  • EPSS 0.29%
  • Veröffentlicht 16.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

  • EPSS 0.19%
  • Veröffentlicht 16.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.

  • EPSS 3.31%
  • Veröffentlicht 16.03.2017 14:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies ...

  • EPSS 0.38%
  • Veröffentlicht 25.11.2016 18:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.

  • EPSS 0.12%
  • Veröffentlicht 25.11.2016 18:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.

  • EPSS 0.23%
  • Veröffentlicht 25.11.2016 18:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.