SB2016092715 - Access security bypass in Drupal Drupal
Published: September 27, 2016 Updated: December 5, 2020
Security Bulletin ID
SB2016092715
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Access security bypass (CVE-ID: CVE-2016-7572)
The vulnerability allows a remote authenticated user to download configuration export on the target system.The weakness is caused by improper access control. Via the "system.temporary" route attackers can download the whole config export.
Successful exploitation of the vulnerability may result in downloading of configuration export on the vulnerable system.
Remediation
Install update from vendor's website.