SB2016091909 - Validation Bypass in Drupal Drupal
Published: September 19, 2016
Security Bulletin ID
SB2016091909
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Validation Bypass (CVE-ID: N/A)
The vulnerability allows a remote user to submit invalid user's names and e-mail adresses.The weakness is caused by validation bypass and may lead to submission of not valid user's data.
Successful exploitation of the vulnerability results in not valid user's credentials submission.
Remediation
Install update from vendor's website.