Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in a URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal me aliases模块权限许可和访问控制漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。me aliases是其中的一个提供了到当前用户相关页面的快捷方式的模块。 Drupal me aliases模块6.x-2.10之前6.x-2.x版本和7.x-1.2之前7.x-1.x版本中存在安全漏洞。远程攻击者可通过在URL中提交带有用户id的‘me’利用该漏洞使用‘me’参数处理器访问Views。
CVSS Information
N/A
Vulnerability Type
N/A