Lucene search

K
drupalDrupal Security TeamDRUPAL-SA-CONTRIB-2016-009
HistoryMar 02, 2016 - 12:00 a.m.

Prepopulate - Moderately Critical - Multiple Vulnerabilities - SA-CONTRIB-2016-009

2016-03-0200:00:00
Drupal Security Team
www.drupal.org
7

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0.967

Percentile

99.7%

The Prepopulate module allows form fields to be pre-populated in the request.

The Prepopulate module does not adequately prevent a user from overwriting arbitrary parts of $_REQUEST. It also does not prevent pre-populating certain fields that are not displayed or manipulating markup fields to alter elements of the user interface.

CVE identifier(s) issued

  • CVE-2016-3187
  • CVE-2016-3188

Versions affected

  • Prepopulate 7.x-2.x versions prior to 7.x-2.1.

Drupal core is not affected. If you do not use the contributed Prepopulate module, there is nothing you need to do.

Solution

Install the latest version:

  • If you use the Prepopulate module for Drupal 7.x, upgrade to Prepopulate 7.x-2.1

Also see the Prepopulate project page.

Reported by

Fixed by

Coordinated by

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS

0.967

Percentile

99.7%

Related for DRUPAL-SA-CONTRIB-2016-009