vulnerability
Drupal: CVE-2016-9449 : Inconsistent name for term access query - SA-CORE-2016-005
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:L/Au:S/C:P/I:N/A:N) | 2016-11-25 | 2017-08-02 | 2024-11-27 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
2016-11-25
Added
2017-08-02
Modified
2024-11-27
Description
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
Solution(s)
drupal-cve-2016-9449-1drupal-cve-2016-9449-2

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.