Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal 核心BlogAPI模块安全绕过漏洞
Vulnerability Description
Drupal中的核心BlogAPI模块没有正确的确认一个Drupal内部格式的未明内容字段,远程认证用户可以借助修改过的字段值,来绕过设置的访问限制。
CVSS Information
N/A
Vulnerability Type
N/A