Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal 安全漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal 6.38之前6.x版本和7.43之前7.x版本的User模块中存在安全漏洞,该漏洞源于程序允许使用不同的方式调用user_save() API。攻击者可通过在保存账户前向表单或数组中添加数据利用该漏洞获取所有角色权限。
CVSS Information
N/A
Vulnerability Type
N/A