Lucene search

K
nvd[email protected]NVD:CVE-2012-5557
HistoryDec 03, 2012 - 9:55 p.m.

CVE-2012-5557

2012-12-0321:55:02
CWE-264
web.nvd.nist.gov

3.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, does not properly assign roles when there are more than three roles on the site and certain unspecified configurations, which might allow remote authenticated users to gain privileges by performing certain operations, as demonstrated by changing a password.

Affected configurations

NVD
Node
user_read-only_projectuser_readonlyMatch6.x-1.0
OR
user_read-only_projectuser_readonlyMatch6.x-1.1
OR
user_read-only_projectuser_readonlyMatch6.x-1.2
OR
user_read-only_projectuser_readonlyMatch6.x-1.3
OR
user_read-only_projectuser_readonlyMatch6.x-1.xdev
OR
user_read-only_projectuser_readonlyMatch7.x-1.0
OR
user_read-only_projectuser_readonlyMatch7.x-1.1
OR
user_read-only_projectuser_readonlyMatch7.x-1.2
OR
user_read-only_projectuser_readonlyMatch7.x-1.3
OR
user_read-only_projectuser_readonlyMatch7.x-1.xdev
AND
drupaldrupalMatch-

3.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.3%

Related for NVD:CVE-2012-5557