CVE-2017-6931
- EPSS 1.07%
- Veröffentlicht 01.03.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:50
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module...
CVE-2017-6932
- EPSS 1.17%
- Veröffentlicht 01.03.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:50
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick ...
CVE-2015-7943
- EPSS 1.77%
- Veröffentlicht 18.10.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and ...
CVE-2015-2749
- EPSS 1.46%
- Veröffentlicht 13.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
CVE-2015-2750
- EPSS 1.38%
- Veröffentlicht 13.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
CVE-2015-7880
- EPSS 1.39%
- Veröffentlicht 13.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.
CVE-2017-6919
- EPSS 1.61%
- Veröffentlicht 20.04.2017 02:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
CVE-2017-6377
- EPSS 1.89%
- Veröffentlicht 16.03.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
CVE-2017-6379
- EPSS 0.78%
- Veröffentlicht 16.03.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
CVE-2017-6381
- EPSS 3.9%
- Veröffentlicht 16.03.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies ...