Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Gábor Hojtsy

Pesquisador deDrupal Security Team
#39528de 56,337
7.5CVSS total
Vulnerabilidades · 1
PT-2016-5394
7.5
2016-04-12
Drupal · Drupal · CVE-2016-3165
**Name of the Vulnerable Software and Affected Versions** Drupal versions prior to 6.38 **Description** The issue concerns the Form API in Drupal, which ignores access restrictions on submit buttons. This might allow remote attackers to bypass intended access restrictions by submitting a form with a button that has `#access` set to FALSE in the server-side form definition. **Recommendations** For versions prior to 6.38, update to version 6.38 or later to resolve the issue.