Lucene search

K
cve[email protected]CVE-2012-5557
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-5557

2022-10-0316:15:32
CWE-264
web.nvd.nist.gov
26
drupal
user read-only
cve-2012-5557
security vulnerability
remote authentication

3.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain operations, as demonstrated by changing a password.

Affected configurations

NVD
Node
user_read-only_projectuser_readonlyMatch6.x-1.0
OR
user_read-only_projectuser_readonlyMatch6.x-1.1
OR
user_read-only_projectuser_readonlyMatch6.x-1.2
OR
user_read-only_projectuser_readonlyMatch6.x-1.3
OR
user_read-only_projectuser_readonlyMatch6.x-1.xdev
OR
user_read-only_projectuser_readonlyMatch7.x-1.0
OR
user_read-only_projectuser_readonlyMatch7.x-1.1
OR
user_read-only_projectuser_readonlyMatch7.x-1.2
OR
user_read-only_projectuser_readonlyMatch7.x-1.3
OR
user_read-only_projectuser_readonlyMatch7.x-1.xdev
AND
drupaldrupalMatch-

3.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

Related for CVE-2012-5557