Search CVE reports
41 – 50 of 137 results
Not in release
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the...
1 affected package
drupal7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | — | — | — | — |
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember...
2 affected packages
drupal7, symfony
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |
symfony | Not affected | Not affected | Not affected | Vulnerable |
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to...
2 affected packages
drupal7, symfony
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |
symfony | Not affected | Not affected | Not affected | Vulnerable |
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related...
2 affected packages
drupal7, symfony
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |
symfony | Not affected | Not affected | Not affected | Vulnerable |
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated...
1 affected package
drupal7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |
Some fixes available 3 of 29
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property,...
5 affected packages
drupal7, jquery, node-jquery, mediawiki, otrs2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |
jquery | Not in release | Not in release | Not affected | Fixed |
node-jquery | Not affected | Not affected | Not affected | Vulnerable |
mediawiki | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
otrs2 | Not in release | Needs evaluation | Not affected | Needs evaluation |
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a...
1 affected package
drupal7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one...
1 affected package
drupal7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | — | — | — | Not in release |
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar://...
1 affected package
drupal7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |
Some fixes available 1 of 4
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that...
1 affected package
drupal7
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
drupal7 | Not in release | Not in release | Not in release | Not in release |