6 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.2 Medium
AI Score
Confidence
Low
0.002 Low
EPSS
Percentile
60.8%
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
CPE | Name | Operator | Version |
---|---|---|---|
drupal:drupal | drupal | lt | 5.11 |
drupal:drupal | drupal | lt | 6.5 |