Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Prior hook_comments API 安全绕过漏洞
Vulnerability Description
Drupal 4.7.8版本之前的4.7.x版本和5.3版本之前的5.x版本中的hook_comments API没有绕过公开状态,攻击者可以绕过限制并触发具有非公开评论模块的e-mail,如(1) Organic 族权和(2) 订阅。
CVSS Information
N/A
Vulnerability Type
N/A