Information disclosure in Drupal - CVE-2016-9449
Published: November 25, 2016 / Updated: August 9, 2020
Vulnerability identifier: #VU40008
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9449
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to gain access to sensitive information.
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
Affected software
Drupal
Arch Linux
Fedora
drupal7
Arch Linux
Fedora
drupal7
How to mitigate CVE-2016-9449
Install update from vendor's website.
drupal7 - addressed in versions 7.52-1.el5, 7.52-1.el6, 7.52-1.el7, 7.52-1.fc23, 7.52-1.fc24, 7.52-1.fc25