CVE-2016-3165 (drupal)

CVE-2016-3165 (drupal)

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

Source: CVE-2016-3165 (drupal)

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다