CVE-2016-3169

HIGH

Debian Linux < 6.38 - Access Control

Title source: rule
STIX 2.1

Description

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.

References (4)

Core 4
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/02/24/19
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/03/15/10
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3498
Patch, Vendor Advisory x_refsource_confirm
https://www.drupal.org/SA-CORE-2016-001

Scores

CVSS v3 8.1
EPSS 0.0102
EPSS Percentile 77.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (41)
debian/debian_linux 7.0
debian/debian_linux 8.0
drupal/core 6.0 - 6.38Packagist
drupal/drupal 6.0 (10 CPE variants)
drupal/drupal 6.1
drupal/drupal 6.2
drupal/drupal 6.3
drupal/drupal 6.4
drupal/drupal 6.5
drupal/drupal 6.6
... and 31 more
Published Apr 12, 2016
Tracked Since Feb 18, 2026