Vulnerability from drupal
Published
2021-09-22 17:09
Modified
2023-08-11 16:51
Summary
Details
This module provides a powerful interface for managing a taxonomy vocabulary. A vocabulary gets displayed in a dynamic tree view, where parent terms can be expanded to list their nested child terms or can be collapsed.
The module does not take the correct user permissions into account, allowing an attacker to delete and move terms.
The issue is mitigated by the fact that an attacker must have permission to create terms in the targeted vocabulary.
Credits
Klaus Purer
www.drupal.org/user/262198
{
"affected": [
{
"database_specific": {
"affected_versions": "\u003c2.0.6"
},
"package": {
"ecosystem": "Packagist:https://packages.drupal.org/8",
"name": "drupal/taxonomy_manager"
},
"ranges": [
{
"database_specific": {
"constraint": "\u003c2.0.6"
},
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.6"
}
],
"type": "ECOSYSTEM"
}
],
"severity": []
}
],
"aliases": [],
"credits": [
{
"contact": [
"https://www.drupal.org/user/262198"
],
"name": "Klaus Purer"
}
],
"details": "This module provides a powerful interface for managing a taxonomy vocabulary. A vocabulary gets displayed in a dynamic tree view, where parent terms can be expanded to list their nested child terms or can be collapsed.\n\nThe module does not take the correct user permissions into account, allowing an attacker to delete and move terms.\n\nThe issue is mitigated by the fact that an attacker must have permission to create terms in the targeted vocabulary.",
"id": "DRUPAL-CONTRIB-2021-035",
"modified": "2023-08-11T16:51:09.000Z",
"published": "2021-09-22T17:09:11.000Z",
"references": [
{
"type": "WEB",
"url": "https://www.drupal.org/sa-contrib-2021-035"
}
],
"schema_version": "1.7.0"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…