SB2016092715 - Access security bypass in Drupal Drupal



SB2016092715 - Access security bypass in Drupal Drupal

Published: September 27, 2016 Updated: December 5, 2020

Security Bulletin ID SB2016092715
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Access security bypass (CVE-ID: CVE-2016-7572)

The vulnerability allows a remote authenticated user to download configuration export on the target system.
The weakness is caused by improper access control. Via the "system.temporary" route attackers can download the whole config export.
Successful exploitation of the vulnerability may result in downloading of configuration export on the vulnerable system.

Remediation

Install update from vendor's website.