Description
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
Published: 2016-09-09
Score: 8.8 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-550-1 drupal7 security update
EUVD EUVD EUVD-2022-3829 The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
Github GHSA Github GHSA GHSA-frqf-9qr4-6vxf Drupal Saving user accounts can sometimes grant the user all roles
History

No history.

Subscriptions

Debian Debian Linux
Drupal Drupal
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T01:22:20.748Z

Reserved: 2016-07-13T00:00:00.000Z

Link: CVE-2016-6211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-09-09T14:05:08.517

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-6211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses