CVE-2016-6212

medium

Description

The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypass intended access restrictions and obtain sensitive Statistics information via unspecified vectors.

References

https://www.drupal.org/node/2749333

https://www.drupal.org/SA-CORE-2016-002

http://www.securityfocus.com/bid/91230

http://www.openwall.com/lists/oss-security/2016/07/13/7

http://www.openwall.com/lists/oss-security/2016/07/13/4

Details

Source: Mitre, NVD

Published: 2016-09-09

Updated: 2016-11-28

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium