Lucene search

K
cvelistRedhatCVELIST:CVE-2012-5557
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-5557

2022-10-0316:15:32
redhat
www.cve.org
cve-2012-5557
drupal
user read-only module
privilege escalation
vulnerability

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain operations, as demonstrated by changing a password.

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

Related for CVELIST:CVE-2012-5557