vulnerability
Drupal: CVE-2016-3169 : Saving user accounts can sometimes grant the user all roles - SA-CORE-2016-001
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | Apr 12, 2016 | Aug 2, 2017 | Nov 27, 2024 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Apr 12, 2016
Added
Aug 2, 2017
Modified
Nov 27, 2024
Description
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
Solutions
drupal-cve-2016-3169-1drupal-cve-2016-3169-2
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.