Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- Drupal / Drupal10.5.12
- Drupal / Drupal core10.6.0 – 10.6.11
- Drupal / Drupal core11.2.0 – 11.2.14
- Drupal / Drupal core0.0.0 – 10.5.12
- Drupal / Drupal core0.0.0 – 11.0.*
- Drupal / Drupal core0.0.0 – 11.1.*
- Drupal / Drupal core11.3.0 – 11.3.12
References
Updated 5m ago · 8 sources